Thanks for the walkthrough.
So, to clarify, there would be no redundancy in the DNS servers? You would direct to ns1/2.poolname.com which would then send requests to the nearest capable pool.
A DNS-reflection attack of any scale, including the Mirai botnet, would then topple the entire system.