Catch all rule - route all unmatched domains to a catch all service? Letsencrypt?

In addition to this, for the TLS, i would suggest to issue a wildcard certification *.mynewdomain.com, so it works over all your subdomains.