(edit: although I'm a DevOps engineer and I wrote my own subdomain registration service, so my preference will certainly not match others).
(edit: although I'm a DevOps engineer and I wrote my own subdomain registration service, so my preference will certainly not match others).
Sure, that's what you're paying them for. Cloudflare is not a "dumb" domain registrar, they are an integrated service.
> Getting a TLS certificate is pretty quick
Most of the time, yes. Sometimes there are outages or whatever. It makes sense to just get it done ASAP.
Distributing that TLS certificate to their edge network may take some time as well, and who knows what other internal prep they need to do.
If you make a CAA record on Cloudflare then they add extra invisible CAA records which authorize the ~4 different CAs they use for CDN certificates. They really assume you're using the whole stack, not just DNS.
Do you know of a registrar that doesn't do that?
> Many (most?) registrars add DNS you didn't explicitly ask for
This relates to TLS since DNS records can be used to request a TLS certificate, but yes, those show in the certificate transparency log, so that you can check. But it won't tell you about other DNS records that may be used for various other purposes.
In the case of cloudflare, it means not being able to use the majority of their services.