@kemona_halftau @skydotbit because then anyone who has previously owned a domain (or had control of it at any point) can impersonate anyone else who has it in the future. with the current system where any cert signed by a CA for the right hostname is automatically trusted (and not everything checks revocation (for example neither curl nor wget complains about https://revoked.badssl.com/)), that would be a terrible idea.