I could also maybe implement some kind of authentication in the future.
I think you should. Otherwise you are just asking for a DoS attack

Lack of authentication doesn't mean there are no other DDoS mitigation measures implemented. Just saying...

Btw, you messed the quotes up, that was TryNinja's quote.