a .tesla.com certificate might well enable more shenanigans than a .pool.ntp.org cert.
That points to a glaring hole in the modern-day automated web PKI, not Tesla's dangling DNS record.
Hell, they issue certificates to IP addresses now. For cloud systems, ownership of an IP could be a few hours.
This has almost certainly been deemed an acceptable risk.
Hope there are no sensitive *.tesla.com cookies out there...