I believe the TXT record validation is only an additional measure, eg to prevent a random developer from registering/uploading a package like org.apache.http2. Surely other authentication methods are used in practice.
I find it hard to believe any high profile organization would allow their domains to expire, or else they would also lose e-mail and websites, right?