Doesn't TOTP use current time as part of the challenge? Why couldn't a refinement of TOTP add the domain name as a further element?
* Most users have no idea what a domain name is.
* It is tedious to compare the domain name character by character.
* Phishing sites have used many UI tricks historically to make their domain name look authentic (e.g lookalike Unicode characters).
The key part of FIDO protocol is that it prevents the user from getting the code intended from one domain and sending it to a different domain.
And like the other reply stated, if you can't mathematically tie them together, you have to rely on the user validating the domain (which you can't).