Many people, including myself, tend to look at .arpa and think "oh yes, thats PTR queries" but forget the DNS doesn't have a global rule that ONLY the PTR query can be sent to the domain.
It's just a domain. You can put anything into your zone. A, AAAA, PTR, TXT, you can even put HESIOD records if you want to party like its Kerberos nineteen ninety IV.
But why
You can get a TLS certificate on .arpa.
https://crt.sh/?q=%25.arpa&exclude=expired&group=none
There are websites as well
Do these free HE assigned IPv6 prefix(es) just remain valid indefinitely even when not actually being used/routed?
You might not even need to go through HE. Many ISPs allow you to set your own PTR records / rDNS delegations if you ask them, since this is also necessary to host email servers.
As the post calls out, most certificate authorities will not issue certs against .arpa domains. I found this out the hard way when paying for CloudFlare's Advanced Certificates add-on for an .arpa domain I had successfully delegated and registered.
They return failures and exceptions when attempting to generate the certificate for the .arpa domain and then I spent months trying to get a refund (they are very slow to respond) and only caved once I threatened a chargeback for the service not working as advertised.