It wasn't clear to me where this should be submitted, but we have received security alerts as our domain does not have any CAA records (https://letsencrypt.org/docs/caa/), I believe a single CAA record referencing letsencrypt should be sufficient, although we will need to verify any host under our domain, and make sure all are covered (dashboards and other things).