X.509 for SSL and TLS
The "certificates" that identify a website for "https" secure browsing.
Other tools exist to strengthen security and domain ownership beyond "commercial certs" offered by common vendors.
Domain Name System Security Extensions
DNS-based Authentication of Named Entities
The use of a CA or "commercial" certificate does not exclude the use of DANE, of course. If you enable DNSSEC on your domain, there is no reason why you cannot authorize your current "commercial" X.509 certificate via DANE, as well, independently of any commercial certification.