This would help detecting legit BOTs for sure, but as Origin you would still have the same issue than before, as you still need to be able to discern between "real" Users and all the malicious Traffic.
The Amount of "good" bots is way smaller than that, and by good behavior and transparent data much easier to identify even without this kind of stuff.
So to make real use of this, Users would also need to do this and suddenly "privacy hell" would be too kind to call this.
It does not sound extreme, unfortunately. Meanwhile the malicious traffic would keep their activity with spoofed-and-so-on certs, from the very beginning.
Most likely passive DNS data, if you use your subdomain you do DNS queries for it. If you use a DNS server to resolve your domains that shares this data, it can be picked up by others.