I've started hosting DoT/DoH endpoints, and even with a few layers of QoS/rate-limiting enabled, I wonder how long it will be until I get to be part of a DNS amplification DDoS.