We theoretically could, but those certificates would show up in CT logs. (For quick & easy monitoring, you can get an RSS feed for your domain on https://crt.sh/, but it's not the most reliable service.) It would be a reputation killer if we did that, just like it would be for your DNS provider or ISP.
masfuerte|6 months ago
benburkert|6 months ago
With this we could issue or revoke a new certificate, but we couldn't impersonate them because we don't control the rest of their DNS.