Agree.
It was proposed weeks ago to add DNS TXT record verification to NIP-05, so that NIP-05 could work with just a DNS query.
No webserver, no HTTPS, no certificate/CA, just a DNS query.
But it was rejected for the sake of simplicity.
Which is understandable too, by the way.