Would be good to be able to point at any domain, a common issue with debugging cert stuff is working out which cert is being presented, TLS level, cipher suites etc are being negotiated.
That’s true, but I was wary of running what would essentially be an open TCP relay. Also, I don’t currently bundle a comprehensive set of root certs in subtls, nor support all ciphers or signing methods.