Sorry how does that help if the attackers purchase a new "valid" SSL certificate since they control the DNS and thus email?
Makes sense because it keeps HSTS from the lockout scenario that makes HPKP so scary.
There is no strong defense against this as a website. With an app the solution would be certificate pinning. You could try HPKP but that comes with a host of issues and I think it is being deprecated.
I think unless a TLD registrar gets hijacked that mitigates the attack on your own DNS after the NS TTL
Here though, people using area53 for DNS probably can't move away from it as they are stuck on amazon.