More the DNS and DNSSEC and the like. Whether or not there is actually an HTTP server responding is irrelevant to whether or not those securely point anywhere but a malicious system.
It's just part and parcel of owning the domain. It's one thing to have the domain, but the next step is offering an active website so that people that actually put that domain in a browser can see it's a placeholder.
When you own a domain, you can choose not to serve anything on HTTP/S, and still nobody can come and serve some other website on your domain, because they don’t control the DNS records.
HTTP is used by billions of people while SSH is not. It should be pretty apparent. Why do people answer my phone calls and texts but everyone is ignoring my smoke signals?