It turns out that internal recDNS is underprovisioned in eqiad given current load. 80% of the load on eqiad recdns is lookups for statsd.eqiad.wmnet, which seem to be made multiple times per MW appserver query, and never cached by those clients (presumably for usual PHP reasons).
https://gerrit.wikimedia.org/r/c/operations/puppet/+/554618 dropped us from ~70k packets-per-second on each recdns host to about 12k pps. But this is a kludge, and should be rolled back when we have the capacity (10G NICs coming Soon, which will likely help), or when we work around it other ways (such as with a local stub resolver on every host [with a max-ttl set to only a minute or two, so we don't create more of a mess around purging bad records]).