Are there any valid technical use-cases for IP spoofing? i.e. setting the source address of a UDP packet as one outside the originating network? For example, on the server side, BGP hijacking and anycast routing are enabled by the same bug or feature, depending how you look at it.
In the sense of where bcp38 should be applied? I agree that it should be POSSIBLE, through some administrative means, to prove an entity does in fact own a given address range and to request the additional privilege of sending data as if it were from that range.
This would be how a non-ISP obtains an independent entity allocation and sets up multi-homing.
It's also how data-centers would allow a co-located server to do the same (and should require the same steps).
At the more backbone levels it should be possible to automatically determine IF ingress packets are from authorized sources. Failure to do this, and failure to respond in a timely manor to filtering invalid ingress, should result in 1) those packets being rejected (and visible rejection notices sent back) 2) if the issue persists, the source of that address being blocked /entirely/ from the Internet, as a non-administered system.
Grace time should likely depend on the severity of the issue (volume of problem traffic/load on the upstream filtering capacity).