99% of people who could benefit from owning a domain should never have to know what a DNS record or TLS cert is. This should all be managed by apps through a simple delegation system built on OAuth2.
You log on to bsky.app, they say, "want to connect a domain?". You say yes and get redirected to your domain registrar, where you grant access to for bsky.app to have control over bsky.example.com until you revoke access.
DomainConnect[0] should solve this but in practice it's turned out to be very gatekeepy in my opinion.