Of course - but that requires the owner to know they were attacked, know the attacker added a TXT verification, potentially overcome fear of deleting it breaking something unexpected, etc.
(Which in general would be a good practise anyway, because many services do use domain validation processes similar to what you propose)