Indeed, your domain registrar can always rug you by pointing a record to their own server and issuing a fresh https certificate.
Meanwhile DNSSEC is easier to verify, nostr:npub185h9z5yxn8uc7retm0n6gkm88358lejzparxms5kmy9epr236k2qcswrdp wrote some Rust code for it, unlike https which only browsers can.
Privacy downside in is having to fetch the TXT record with the proof somehow, e.g. with DNS-over-HTTP. But you could have relays share the records.