@laurelrusswurm @boneidol CAs “out of band verification” is also astonishingly weak. If you can receive e-mail at certain domain addresses, you’re likely able to get at least the standard cert. (Or if you sign up for #Cloudflare, they’ll automatically get a cert for you, a trick that phishers on misspelled domains have used repeatedly.)