The protocol asserts that you have control over the domain, and over a machine that can be accessed at the domain's A record. If you can make your machine appear to be at google.com from the perspective of LetsEncrypt for the duration of the request process, you can get a cert from them.
This is standard for all domain-validation-only certificate authorities, i.e. the cheapest cert you can get from any given company.
This is standard for all domain-validation-only certificate authorities, i.e. the cheapest cert you can get from any given company.