LetsEncrypt recently reiterated the need for setting TLSA records for all of their certificates, including backup ones, not just the current X3. Here you can find convenient cheat-sheet with ready-to-use DNS records and appropriate hashes:

Note that X3 expires in March 2021 so while it's not a "had to be done yesterday" task, it's also not "let's put it into our todo for a decade" :)

