- The problem is that you are only partial correct. Join the list require manually human confirmation.
Leaving the list only require the change of NS entry for the domain. And as long as the public suffix list
is currently be handled it always take some time to be on the list and to get the list integrated to LE
first staging and later production. Since the removal also take this time it is much more than an 7 days gap. - Since the domains are “private” owned the owner can always change the DNS record, request an cert for
an subdomain an change it back. - The certificate is called DV which means domain validated in effect the cert is in this case only host validated.
To be honest it is nice to have an green lock but for tls-sni-01 and http-01 it have the same quality as trust by first visit.