If users delegate their DNS to you, what's stopping you issuing a certificate to yourself for their site?
With this we could issue or revoke a new certificate, but we couldn't impersonate them because we don't control the rest of their DNS.
If that were true, nobody would need signed certificates in the first place.
Whether or not something like this makes sense to you is probably a question of your personal threat model.
https://crt.sh for point in time checks, https://sslboard.com for comprehensive oversight (disclosure: I'm the founder)