A certificate has to be signed by a trusted CA (one your browser already trusts).
A DNS provider could mint a self-signed cert for pornhub.com, but your browser would reject it immediately.
Even if they tried to trick a real CA, Certificate Transparency (CT) would expose the bogus certificate:
https://en.wikipedia.org/wiki/Certificate_Transparency
Instead, NextDNS is very likely abusing the EDNS Client Subnet feature to provide website operators with a spoofed client location. Much more simple and less nefarious.