When registering for an SSL cert, I was able to validate that I "owned" the domain I was creating the cert for by having a valid @domain.com email address. If I worked for a large company, say Microsoft or something, and have a valid me@microsoft.com email address, how am I prevented from being able to create a valid SSL cert for microsoft.com?
Maybe Microsoft has something in place to handle this, but what if the company is a bit smaller and doesn't have anything in place?