I noticed there is a new DNS record which can be added (sorry, I am not sure how long it was present) called CAA
This is for SSL DNS CA, so we are now using it and quallys test show its works lovely.
We have our CAA set to Lets Encrypt, but if a client uses their own, you will need to amend or delete the CAA record accordingly.
Further reading for CAA here
I hope that helps a little and kudos to Interwox