I'm not sure what that would solve. You would still need some central entity to sign the DNS TXT record, to ensure that the HTTPS client does not use a tampered DNS TXT record.
Besides, if someone has access to your TXT records then chances are they can also change A records, and you've lost already.