TLSA (DANE) - RTC 6698.
Storing TLS-cert in DNS is a bad idea and kinda defeats the purpose.
However, the idea with TLSA-record is that owners of the domain can verify the "visitor" that the certificate is valid - DNSSEC required ofcourse.
Postfix already have support for it called DANE, and if I remember correctly - about 0.3% of SMTP-servers online actually implemented it (2019 data)