In most of our domains, we have generically templated in hostnames for both donate.$domain and www.donate.$domain. The former works fine with TLS, but the latter is an insecure redirect in all cases that I checked. We should probably remove the www's, as otherwise we'd have to increase our cert count/costs by ~50% to get either www.donate.$domain or *.donate.$domain for all of our project domains.
Related but probably much more complex, we have this in the wikimedia.org zone:
wikimedia.org:bounce.email.donate 1H IN A 74.121.50.42 wikimedia.org:bounce.email.donate 1H IN MX 5 bounce.email.donate wikimedia.org:bounce.email.donate 1H IN TXT "v=spf1 ip4:74.121.51.111 ip4:208.80.155.11 -all" wikimedia.org:email.donate 600 IN DYNA geoip!text-addrs-v4/eqiad wikimedia.org:email.donate 1H IN MX 10 reply.email.donate wikimedia.org:email.donate 1H IN MX 20 mail3880.email.donate wikimedia.org:email.donate 1H IN TXT "v=spf1 ip4:74.121.51.111 ip4:208.80.155.11 -all" wikimedia.org:mail3880.email.donate 1H IN A 74.121.51.111 wikimedia.org:mail3880.email.donate 1H IN MX 5 mail3880.email.donate wikimedia.org:mail3880.email.donate 1H IN TXT "v=spf1 ip4:74.121.51.111 ip4:208.80.155.11 -all" wikimedia.org:reply.email.donate 1H IN A 74.121.50.42 wikimedia.org:reply.email.donate 1H IN MX 5 reply.email.donate wikimedia.org:reply.email.donate 1H IN TXT "v=spf1 ip4:74.121.51.111 ip4:208.80.155.11 -all" wikimedia.org:links.email.donate 1H IN CNAME recp.mkt41.net. wikimedia.org:open.email.donate 1H IN CNAME open.mkt41.net. wikimedia.org:www.email.donate 1H IN CNAME wikimedia.org.
I'm not sure what to make of all of those. They mostly seem to be hosted with http://www.silverpop.com/ (via mkt41.net ), but www.email.donate is ours and doesn't match TLS certs either.