[SOLVED] Let's Encrypt certificate is issued at the wrong (default?) domain name

WhyNotPadlock: Results
Self Signed Certificate: Your SSL certificate appears to be self signed.
Domain Matching: Your SSL certificate does not match your domain name!
Protected Domains:: c98998a8c6f7111f0299849a6d614c5c.a3f739e84842e9c89266624bd1bbce74.traefik.default

docker-compose: here
CERT_RESOLVER is set to letsencrypt, DOMAIN is set, config seems fine, and I am left scratching my head...

Edit:

related log:

"Unable to obtain ACME certificate for domains \"arvigeus.one,*.arvigeus.one\" : unable to generate a certificate for the domains [arvigeus.one *.arvigeus.one]: error: one or more domains had a problem:\n[*.arvigeus.one] time limit exceeded: last error: NS ns3.linode.com. did not return the expected TXT record [fqdn: arvigeus.one., value: zke58AcEZ4Y0s2YJpI08YfKABk9yCq3ezbymbL9-PBE]: \n[arvigeus.one] time limit exceeded: last error: NS ns3.linode.com. did not return the expected TXT record [fqdn: arvigeus.one., value: 4t5ZBYdYOUhN-4FIE75eCswcdHCxS-I4SGjhq27_sWk]: \n" providerName=letsencrypt.acme