I ran my own small-business/family mail server for a little over a decade. Spam is out of control.
UCEPROTECT and other RBLs are just lists of text files. They do not block anything. As the mail administrator, you can choose what you do with a UCEPROTECT listing.
When I ran my mail server, I had UCEPROTECT tied into SpamAssassin, so that a UCEPROTECT listing by itself wouldn't block email; it would just raise the "spam probability rating" up.
UCEPROTECT is not a huge professional thing; it's "some guy" who's been running it, effectively, for free since the very early 2000s. No one is obligated to use it. If someone is being blocked by it, they need to contact the mail admin. UCEPROTECT just lists problematic hosts.
On to WHY DO and no CF/AWS? I don't know.. I'm not the "some guy" running the thing. But if I had to guess, it's that DO doesn't respond to spam complaints[1]. Whereas CF/AWS, while they host spammers, will take action against reported spammers.
[1] https://www.reddit.com/r/sysadmin/comments/1cwilrc/does_digi...