In more than one way. Selling domain names is one. Selling "threat intelligence" extracted from DNS queries another.

@liw Perhaps we could encourage Let's Encrypt to run Let's Register as a related service.

That way they can get rid of the whole concept of "Domain Validated" TLS certificates in one go, replacing them with "Someone-somewhere (might be a something, we can't be sure) once said this was OK" TLS certificates ...

