By default it seems that Let's Encrypt will only secure the main naked domain, www and webmail, as per my first screenshot-1
However, our situation is different and we need to Wildcard secure all domains by default (when created) and then assign the certificate to the mail domain, as per...