in the meantime i think that it's important to make a loud notice of this in NIP-05 that cors wildcard header needs to be set so as to not disadvantage web app users with strict CORS policy
Discussion
AFAIK there is already such warning in the nip05 spec.
indeed it is
nostr:npub1ye5ptcxfyyxl5vjvdjar2ua3f0hynkjzpx552mu5snj3qmx5pzjscpknpr perhaps you should make a note on the failed CORS error display that is just a questionmark in orange and a tooltip which says "it cannot be determined whether the NIP-5 exists or if it is not sending a correct HTTP CORS header, beware"