At least for certificate issuance they can turn it off via a CAA record:
https://en.wikipedia.org/wiki/DNS_Certification_Authority_Au...
https://en.wikipedia.org/wiki/DNS_Certification_Authority_Au...
Now, there are a bunch of things you could do about that, and I believe this cool toy does one of the obvious ones: Don't have any certificates for the problematic domain. The web site isn't in the domain you can mess with. But it would be nice if Let's Encrypt got to this, periodically I check so far each time somebody has pestered them for RFC 8657 recently, so I don't pile on since that's unhelpful.