You don't know that even with DNS validated certificates. There's no separate "entity" claim other than "anybody with DNS record modification rights for a given domain".
You can give out the same claim over DNS directly without any extra third party involvement in the form of CA.
Huh, wow. I kind of thought the whole point of CAs was to do identity verification. It they have dropped that entirely, what is the point?