Typically a service using domain verification will ask you to create a specific, randomly generated TXT or similar record on your domain. After you’ve created the record you click a button or something and they do a query for it.
Only someone with access to DNS for the domain can create such a record.
Suppose:
EXAMPLE.VICTIM.XYZ -> A 1.2.3.4
EXAMPLE.ATTACKER.XYZ -> A 1.2.3.4
EXAMPLE.ATTACKER.XYZ -> TXT whatever verification is needed
DDoSes operate on IPs, not dns names. In the end, the target IP is getting DDoSed anyway.Yes, of course DDoS or any kind of traffic can be pointed at an IP or any arbitrarily created DNS record.
The only way for a “reputable” stress testing platform to validate IP space would be RIR validation via WHOIS or similar, PTR records, etc. Of course this isn’t practical because most people don’t control their IP space or even have the foggiest idea what any of that means (because why should they).
That's why OP specified their DNS record. You buy/use a random domain name you own, point the A record at the IP you wish to attach, and then simply complete the TXT record verification since you have full control over the domain, while the booter resolves the A record to the true target.
No, most (?) DDoS attacks aren’t botnets sending HTTP requests directly, those would have terrible throughput and be trivial to mitigate. Instead they use amplification from third party servers where you send a small packet to get a big packet in response, mistakenly routed to the victim. There’s usually no way to attach a Referer to those, most of which aren’t even HTTP-based.
How else do you imagine this working?