https://mailarchive.ietf.org/arch/msg/dconn/ZBOHz9sE-y7DbGtaaeTiaLlFFoM
I also realised a more dangerous scenario: malicious domain with _domainconnect record pointing to malformed http resource / oversized file etc. (potential DoS of Service Provider), or internal URL of server infrastructure. I think these are additions to Security Considerations I would take.
https://mailarchive.ietf.org/arch/msg/dconn/ZBOHz9sE-y7DbGtaaeTiaLlFFoM