If you want to prove domain ownership, you have to do it at the domain level. The ability to serve a file “www.example.com” in no way demonstrates ownership of “example.com”; it demonstrates that you control www.example.com. If you want to prove ownership of a second level domain you must do it through a record in DNS, or through demonstrating control of something that is publicly known to control the domain such as…
As said multiple times in this thread, the primary way of identifying yourself in this protocol is a TXT record in DNS.
Unless the UI makes it clear it was verified with "non-primary" methods so users can be cautious, any method of verification is essentially "primary" from the user POV.