If the owner does not find out that someone got control of their DNS server, the attacker can do anything with the domain anyhow. Including issuing certs.
(Which in general would be a good practise anyway, because many services do use domain validation processes similar to what you propose)