Evil haxxxor: creates domain name pointed at target it doesn’t own
Innocent stress test site: prove you own this domain by adding cname in the DNS record
EH: sure, heh heh heh
ISTS: performs ddos against target
Requiring the owner to post a file at a specific URL would prove actual control of the server in a way that domain records don't. I can point a domain at whatever server I want, no need for it to be my own.
Typically a service using domain verification will ask you to create a specific, randomly generated TXT or similar record on your domain. After you’ve created the record you click a button or something and they do a query for it.
Only someone with access to DNS for the domain can create such a record.
Suppose:
EXAMPLE.VICTIM.XYZ -> A 1.2.3.4
EXAMPLE.ATTACKER.XYZ -> A 1.2.3.4
EXAMPLE.ATTACKER.XYZ -> TXT whatever verification is needed
DDoSes operate on IPs, not dns names. In the end, the target IP is getting DDoSed anyway.Yes, of course DDoS or any kind of traffic can be pointed at an IP or any arbitrarily created DNS record.
The only way for a “reputable” stress testing platform to validate IP space would be RIR validation via WHOIS or similar, PTR records, etc. Of course this isn’t practical because most people don’t control their IP space or even have the foggiest idea what any of that means (because why should they).
That's why OP specified their DNS record. You buy/use a random domain name you own, point the A record at the IP you wish to attach, and then simply complete the TXT record verification since you have full control over the domain, while the booter resolves the A record to the true target.
How else do you imagine this working?
No, most (?) DDoS attacks aren’t botnets sending HTTP requests directly, those would have terrible throughput and be trivial to mitigate. Instead they use amplification from third party servers where you send a small packet to get a big packet in response, mistakenly routed to the victim. There’s usually no way to attach a Referer to those, most of which aren’t even HTTP-based.