It would be good to have this option since some CAs now only singe SSL certificates when the CAA record is valid. For example the German Telekom uses a CAA dig tool that uses the Google DNS servers by default. If you have a wrong CAA record and get advised to correct them the German Telekom will wait until the changes a present in the Google DNS, they use the Google DNS only and not the actual name server for the domain. So you have to wait for your SSL certificate until the Google DNS reflect the changes.
The German Telekom uses the website https://digwebinterface.com/ to verified CAA records, they only use the default resolver which is 8.8.4.4. Our certificate requests are always NOT DNSSEC domains.
The tip with the TTL is really good, sometimes it's the simplest solutions you do not come up with on your own. Thanks