I still find it slightly nebulous what exactly the condition is that a DV certificate is proving. In practice, it's that at the time of the challenge, the DNS entry (as observed from one or more secret locations on the internet) is under the requester's control.
But couldn't this be archived a lot simpler by having the registrar also be the CA and automatically generate a cert when I update the DNS? Why do we even need separate CAs at all still?