Isn't this how TLS itself already works? "trust on first use"?
SSH is an example of TOFU.
You still can... it just displays a warning message on first use, as does ssh.
A domain can layer on HSTS to that, which directs clients to additionally refuse to trust a new cert for a domain until the one you currently trust has expired.