TL;DR

  • wildcard certificates need DNS-01
  • create the TXT record exactly as your DNS provider expects
  • verify propagation before continuing the challenge
  • remember that manual DNS-01 also means manual renewal unless you automate the provider side