What you are proposing sounds like DANE with TLSA and DNSSec. Great idea but most CC TLDs are still using 1024 RSA ZSKs. Right now PQ DNSSEC is very uncertain. PQ DNSSEC will likely take about 5 more years or so to standardise. And thats too late for companies like Google and Cloudlfare which want to go PQ Crypto by 2029.