I was a lead on Blitz. You’re right that there are ways to get around this domain ownership check, but in practice it was enough of a hurdle to avoid bad actors. Also, I’m pretty sure that these stressors were way more cost effective if your only goal is to DDoS a site.
The idea is that the stress testing site dictates where the file must go, not the user. So for them to run the test, they may need to see a specific file at "subjectsite.com/secretguid"
The idea being that unless you have total domain control, you can't get that file where they want you to put it.
If you use a custom domain with those services you can still place a file anywhere you want.
Sure, but now GitHub can see what domain all the DDoS traffic went through, see who paid for it, and now you've practically giftwrapped a confession.
You could check the existing DNS of a domain, if they're GitHub or Netlify's DNS addresses / IP's then you don't stress those.