You can use any domain you like. I personally have an actual domain that I only use inside my network. This way I can get SSL certs from Let's Encrypt using the DNS challenge which doesn't require any ports being opened. You can use self signed certs but I would strongly suggest using certs from the likes of Let's Encrypt.
Here are 2 pages on this subject
https://github.com/dani-garcia/vaultwarden/wiki/Enabling-HTTPS