Do Not Track was the right implementation (browser-based, activate only once) and it was sabotaged by ad peddlers. It is bad policy that has been reached after every better alternative was rejected.
Do not track has been used by ad companies to track users, it’s one of the datapoints that can be used to identify your fingerprint
The idea is that it'd be illegal to do so. Same as how with GDPR it's illegal to track users who denied tracking, even though technically nothing stops you from doing it.