And at least Let's encrypt actually verifies DNSSEC before issuing certificates. IIRC it will become mandatory for all CA's soon. DNSSEC for a domain plus restrictive CAA rules should ensure that no reputable CA would issue a rogue cert.
$ dig +short letsencrypt.org DS
$For starters you could try `dig +short ds google.com`. It'll give you a flavor of what to expect.
It's the latter.
You're not going to take my word for it, but you could take Geoff Huston's, who recently recorded a whole podcast about this.