I personally like how all this doesn’t seem to require any new protocol or checks. Just plain DNS.
The "well-known" URI scheme[1] was intended to overcome many of these deficiencies, and has worked admirably in other contexts (for example, Let's Encrypt's HTTP-01 challenge scheme[2]). I believe Bluesky also supports a "well-known" flow for domain verification, but it seems like it still isn't the default.
and it looks like it's only resolving domains to DIDs, but not that the DID's owner accepted the domain; so you could make any of your domains point to anyone's DID. The extension would need to use ATP's new protocol to check it.