It sounds like an interesting idea. But I do not really see why it should be more secure that dnssec. You cannot spoof dnssec unless you have access to the dns server the domain is hosted on. If you do have access, you can change the ip address and all perspectives will connect to you instead. Actually dnssec is probably more secure, because it also protects you from doing man-in-the-middle in right front of the server.