For end users, TLS is the key protection. I don't care if my DNS is poisoned, MITMed, or malicious: if the IP address I connect to can't present a valid TLS cert, then I don't proceed.
If you can't securely authenticate your server (as HTTPS/TLS does) you have other problems too.