> If DNS was trustworthy then the entirety of TLS PKI would be entirely redundant

I’m not sure I understand the logic here. To me TLS PKI and DNS are somewhat orthogonal.