Very, very interesting… I forgot the fact that ip addresses can be spoofed in the UDP packets, essentially making DNS resolvers to carry out the attack for botnets.
DNS servers can be used in an DOS amplification attack by sending requests with spoofed ip addresses. So if you don’t take measures to prevent this it’s likely your server will be used in DOS attacks.