That said, even if the attackers in this event didn't spoof the IP address, they would almost certainly have still had a very wide distribution of addresses.
> DNS root name servers that use IP anycast observed this traffic at a significant number of anycast sites.
DNS root name servers are BGP anycasted: without knowing the maintenance routes, any packets you send will get routed to the topologically nearest instance. So, since the traffic source managed to hit multiple, geographically disperse anycast sites we can infer that they were able to generate traffic from worldwide traffic sources.
Even if it were from a single source, it also isn't that hard to find an ISP that doesn't care. (They cost slightly more, but if you're a bad actor, presumably it is worth it.)
Edit:
"I think pretty much any ISP wouldn't let such packets through"
If you google "BCP38", you will find well over a decade of network operators discussing specifically this topic and the reasons why ISPs (and other networks) don't, not to mention all the fun the kvetching and meta-kvetching that accompanies any technical discussion that's lasted so long.
"The solution to this problem, described in RFC2827, which was written some 13 years ago by Paul Ferguson and Daniel Senie, is to block IP packets entering the internet which have source IP addresses which are forged..."
For "typical AS router", is it easy or cheap to block spoofed packets?
I wonder if that test software/website can/should "OUT / Shame" the AS routing subnets as "Major Internet Polluters" and publish a monthly reports to shame that 30% polluters.