What you want to prove to yourself is that if "google.com" is associated with public key "04cafebabe", that association is also visible to everyone else (provided other people follow the same protocol).
The distributed DNS+SSL protocol could look like this (simplified):
1) To register a name "google.com", check that it's not registered yet (see below). If not, create a special Bitcoin transaction ("registration tx") that encodes both the name and the public key of the SSL certificate used by that server.
2) To check who owns the name "google.com", find the earliest "registration tx" on the blockchain (other people could add more, but only the first one is considered valid). If the name is 100 blocks deep, trust the public key associated with it.
The protocol can (and should be) extended to allow transferring the name to new public keys, you may check how Namecoin does it.
What you get in result is that every single user can be sure that they see the same up-to-date public key identifying "google.com" without any trusted Certificate Authorities who have failed at this promise multiple times already.
As a nice side effect, name allocation and trade is also decentralized. If you own name "google.com" and users respect the protocol, no one can take this name from you or censor your sale of that name to someone else. Also, you are free to register your own name without asking for anyone's permission and paying fees.