The trick is to request random top-level domains, where each request will necessarily trigger a lookup to the root.
Further, recent research has shown the number of open DNS resolvers to be in the range of 15-30 million[1].
Since the article describes a single domain name was used in the attack however, that's not what happened here.