When a CA based TLS service is the only option that means CAs control even more. And CAs fuck up, often, intentionally, unintentionally, and because of external pressures. The more people pile in one CA the more pressure. LetsEncrypt is great and I'm glad it exists, but everyone using it is bad for the internet's health.
But it is much different in other contexts like HTTPS (HTTP/2 + HTTP/3) only browsers where now human people are unable to host a visitable website without getting a continued approval from a CA.
Address spoofing and a full MITM are two very different threat models.
1. https://serverfault.com/questions/404840/when-do-dns-queries...
I agree that centralizing on CAs is not great, but I think encrypting DNS is in general a good thing.
> CAs fuck up
Sure, but when a CA fucks up, the security of DoT isn't worse than that of plaintext DNS, is it?
With ephemeral keys being ubiquitous in TLS, you even need an active MITM attack to degrade to plaintext; in the face of a passive eavesdropper, DoT using a completely compromised CA is still a vast improvement from a privacy point of view.