If they use either a proxy or a service like Cloudflare, they can get some of the benefits of SSL/TLS (like preventing MITM attacks at the last-mile such as this one), while still using Tumblr to host their blog.
You don't have to strictly speaking, you can use your own and just resolve in the same manner. You'd just need to monitor the results of a lookup on CF's servers and send back the same response with your own DNS.