This is the perpetual refrain questioning why BCP84 hasn't been universally implemented.  Lack of clue, lack of perceived economic incentive, lack of infrastructure capability (though the natural cycle of equipment upgrades has largely eliminated this issue on networks running even semi-modern gear), apathy, sloth, venality.

In the main, it isn't a question of 'can't' - it's a question of 'won't'.  Which is why Paul was saying that network infrastructure vendors should by default enable various anti-spoofing mechanisms on the gear they well.

