okay fine I just switched all my domains off wildcard CNAMEs because letsencrypt is too smart
it goes to look up _acme-challenge.domain.tld, sees *.domain.tld CNAME domain.tld, and then looks for its validation TXT record on domain.tld when it's actually on _acme-challenge.domain.tld
computers D: