DANE is a protocol that enables verified TLS connections without CAs
wiki.halon.io
wiki.halon.io
[1] There's https://en.wikipedia.org/wiki/Merkle%27s_Puzzles, but it's not really practical when you make it secure and not secure when you make it practical.
And it requires your registrar to not try to perform a malicious attack against you. But at that point, most registrars already have access to a root CA, and your domain - they could easily break your environment.