I have some experience of dealing with this when working for .gov.uk
A registrar can accept an anonymous payment for taxgovuk.gtld and have it live within seconds. The spam messages go out instantly to the victims.
By the time the certificate is seen on the transparency logs and the takedown request sent, it's too late. The criminals have taken what they need and they don't care that the domain is now blocked or on warning lists.
At the risk of sounding too libertarian - do we want domain registrations to be subject to a 24 hour mandatory wait period to see if there are legitimate objections? Should registrars do strong KYC checks on people? Should certain substrings be banned?
I struggle to think of a reasonable way to prevent this which doesn't also harm legitimate users. I don't know what the calculus is between annoying the lawful and frustrating the lawless.
On the other hand, I struggle to think of a reason how harm could come from delayed activation of a registered public name. Can you describe a use case that cannot be solved by opting for a subdomain of an already-existing domain?