Do any DNS resolvers monitor for huge spikes of spoofed results? Is falling back to TCP for those queries likely to break much?
Maybe some sort of challenges? Authentication? Like DNS cookies or something.
For attacks like this, there are thousands to billions of spoofed responses coming in. It's not subtle at all, or very hard to keep track of the domains under fire.
Edit: Oh wait, the queries themselves? That's a very different problem and there's no good solution. Harass more ISPs into implementing filters that drop spoofed IPs from their users.
Also reporting them.