The ISP originating the spoofed packets isn’t apparent to the person receiving the attack. The source is spoofed to the victim’s address so neither the DNS operator nor the victim can see where the spoofed packets originated.
(Also, to people down-voting a genuine question ? wth..)
Who would then have to determine where it's coming into their network from, and go ask that ISP, who would have to do the same, ad nauseum. And all parties would have to be paying enough staff to handle that load in addition to, you know, making sure their services work.
- the DNS operator doesn’t care. These look like normal requests.
- if they did care, asking an ISP to packet trace ingress traffic is not trivial. At any large scale ISP there are hundreds to thousands of direct peers that could have originated that traffic.