> If the point of the domain name for you is marketing, then get one you think is "memorable" and use it as a CNAME. The point for me would be non-marketing uses
This is a very fair and valid point. Thank you for pointing this out.
> to get an SSL cert so I do not have to use a self-signed one when monitoring encrypted egress traffic from the local network
This sounds like you're doing proxying / TLS interception / MITM? If so, you need a signing certificate with authority to sign for any arbitrary name. No vendor provides this for free, and using your own self generated CA is the solution here.
> Best I can get for free is a subdomain of someone else's domain name.
It's unclear what you mean here, as the words you're using are somewhat overloaded, depending on context.
An arbitrary gTLD is not something you can get for free, until we have a better solution for DNS than the current approach.
Anything else is just variations on a subdomain. Heck, technically even a gTLD is a subdomain of the root domain '.', where you don't own anything there either, and are simply getting a subdomain granted to you by the roots.
When you look at it from that perspective, and you're simply looking for something that is unique for you, what's the difference between a subdomain from a dyndns provider, and a subdomain from a registry?