(As an aside, I'd pay for a better-curated DNS infrastructure. For instance, google's font domains of whatever could just resolve to something federated, and that has TLS certs that are trusted by the alternative infrastructure. Google's chain of trust could be on a certificate revocation list.)