You're right Douglas.
I've forgot about this, because we never considered it due to the limitation of 100 SANs per certificate with letsencrypt and this is a problem when you handle 5k+ domains.
Also some customers wouldn't be happy to have their domain listed in the same certificate mixed with other customers domains.
We already had some customers complaining about this on another project where we used SANs.
It can also greatly helps spammers to get the list of domain names handled by the mail server. They can check the SANs list and then try to spam random mailboxes on these domains... A pain :)
Sébastien Riccio
System & Network Admin
https://swisscenter.com