Yes. I used Blitz.io a couple of times; they'd require you to put either a DNS entry in place or upload a file to a specific location in the domain's root.
That doesn't really prevent anyone from attacking a hosting service like GitHub Pages or Netlify, though.
You could check the existing DNS of a domain, if they're GitHub or Netlify's DNS addresses / IP's then you don't stress those.
The idea is that the stress testing site dictates where the file must go, not the user. So for them to run the test, they may need to see a specific file at "subjectsite.com/secretguid"
The idea being that unless you have total domain control, you can't get that file where they want you to put it.
If you use a custom domain with those services you can still place a file anywhere you want.
Sure, but now GitHub can see what domain all the DDoS traffic went through, see who paid for it, and now you've practically giftwrapped a confession.
I was a lead on Blitz. You’re right that there are ways to get around this domain ownership check, but in practice it was enough of a hurdle to avoid bad actors. Also, I’m pretty sure that these stressors were way more cost effective if your only goal is to DDoS a site.
You're right. There are plenty of legitimate companies that offer security services whether it's pentesting or DOS attacks. The dark web/malicious providers normally say something like: "this can only be used on machines you have permission to test" while doing absolutely no verification that the services are owned by the purchaser.