That's what the CAA dns records are meant to prevent. It tells Certificate Authorities which of them are allowed to issue for your domain.
Couple that with most providers requiring you to prove your domain via DNS or organizational status and you narrow the attack window.
Also I'd assume that as the owner of a domain, you'd be able to revoke any certificate for your domain that you didn't create.