> Limiting ANY queries to just TCP would have been a reasonable middle

This was proposed solution, the problem is that in case of attack, against a valid Authoritative service, launched via open resolvers, the open resolvers would just download Gigabits of ANY traffic with TCP. Read about this here: https://fanf.livejournal.com/140566.html

