Computerphile did an interesting video series on this!
Which is good because CAs are useless; they're complete overhead. Back when EV certificates meant something, they were marginally useful, but at this point, we might as well just switch to a TXT record that validates domain ownership. (Obviously, that doesn't protect against DNS MITM attacks, but that's a separate issue.)
I wonder if anyone has tried putting .onion addresses into DNS and have clients treat them like address records...
An onion service's IP address is protected. Onion services are an overlay network on top of TCP/IP, so in some sense IP addresses are not even meaningful to onion services: they are not even used in the protocol.
End-to-end authentication
When a user visits a particular onion, they know that the content they are seeing can only come from that particular onion. No impersonation is possible, which is generally not the case. Usually, reaching a website does not mean that a man-in-the-middle did not reroute to some other location (e.g. DNS attacks).
End-to-end encryption
Onion service traffic is encrypted from the client to the onion host. This is like getting strong SSL/HTTPS for free.
From here: https://community.torproject.org/onion-services/overview/
And there's another good reason for the Tor network: if you run an onion service, the traffic will use only Tor non-exit nodes in the circuit, giving a relief to the exit nodes.
* You don't need a TLS certificate from a public certificate authority, as it is already encrypted end to end
* The exit node cannot attempt to snoop on your traffic (via TLS SNI) or inject content/ads/exploits into your unencrypted traffic
* It reduces load on the exit nodes so they can work on serving traffic to sites that don't have an .onion endpoint
And also it precludes any attacks a malicious exit node could run on your https traffic, like the other comment says