Certificate transparency makes issuance observable

Every publicly trusted certificate is now logged where anybody can read it.

That turns a silent problem into a visible one. If somebody obtains a certificate for your domain that you did not ask for, it appears in the logs, and you can be alerted. It does not prevent misissuance, it makes it detectable, which historically was the harder problem because organisations had no way of knowing it had happened.

More on DNS and domains