edit: your original claim-
> GDPR tries to enforce its rules on servers outside of its territory.
It's enforcing rules on data sent to/from people in the EU and the servers (not just servers ofc), i.e. on companies offering their services to people in the EU. If the companies don't wish to follow the laws of a specific country (or in this case, all EU countries), they're welcome to not provide services to those users.
Since you seem to think the example they gave doesn't count because it's a Californian law not federal (not sure why that matters...), how about stuff like "The FTC engages with competition and consumer protection agencies in other countries to halt deceptive and anticompetitive business practices that affect U.S. consumers." ( https://www.ftc.gov/policy/international ) which includes laws such as COPPA ( https://en.m.wikipedia.org/wiki/Children%27s_Online_Privacy_... )
Or let's say there's a country in Europe where hacking and ransomeware are completely legal, and a company in that country focussed their ransomeware efforts on attacking American companies. Would you argue that either the USA wouldn't care about that because it's outside their jurisdiction, or that they shouldn't care because it's outside their jurisdiction?