Other CAs using WHOIS for validation?

If you're looking for a bit of facepalm about how the Internet is and always has been largely held together by duct tape and bailing wire.

It's a bit of a long read, but essentially these guys were able to register a domain for an old WHOIS server that a lot of major orgs still use because they're using outdated WHOIS clients/libraries. And that lead to the discovery that some of those CAs (not LE) use the WHOIS data to determine the email address for Email based ownership validation.

Glosseary from baseline requirement

Domain Contact: The Domain Name Registrant, technical contact, or administrative contact (or
the equivalent under a ccTLD) as listed in the WHOIS record of the Base Domain Name or in a DNS
SOA record, or as obtained through direct contact with the Domain Name Registrar.

that's where authoritative domain contact is in views of cab forum

Yeah, but it seems that there are TLDs with broken whois servers, and there's no really authoritive list of what whois servers to use that CAs can really rely on always being updated.

See also the Mozilla security list discussion:
https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/FuOi_uhQB6U