NSEC does this.
> An NSEC record can be used to say: “there are no subdomains between subdomains X and subdomain Y.
NSEC does this.
> An NSEC record can be used to say: “there are no subdomains between subdomains X and subdomain Y.
Unfortunately though, the entire PKI ecosystem is tainted if other CAs do not share the same security posture.
[1] https://cabforum.org/working-groups/server/baseline-requirem...
[2] https://www.verisign.com/en_US/company-information/verisign-...
Let's convince all registrars to implement a new standard? ouch.
At that point, it doesn't matter how many vantage points you verify from: all traffic goes to your hijack. It only takes a few seconds for you to verify a certificate, and then you can drop your BGP hijack and pretend nothing happened.
Thankfully there are initiatives to detect and alert BGP hijacks, but again, if your organization does not have a strong security competency, you have no knowledge to prevent nor even know about these attacks.