Do you know if I can use the verification call in cases where I know only the mobile number of the signatory?

You could use the webfinger call and put the mobile number as identifier in the API call.