It looks like it's proxied if you come over IPv4 - which the vast majority of "customers" likely do.
pass in on egress inet to $secondary_ipv4 \
af-to inet6 from $ipv6 to 2a02:a45f:8eaa::2/128
All I get is timeouts and traceroutes with infinite hops. First I tried rdr-to, but that complains of the address family mismatch.It's just there have been others who put a gameboy behind a massive cache, and most requests would come back from the cache server.