A quick update…
I've had this enabled for a few weeks now, with a couple of hundred users a day, over a dozen sites - no complaints received so far.
Final parameters used were 1Kbit/s source address, 50ms delay.
I'll stress again though - this will not prevent DNS tunnelling, it will only slow it, hopefully to the point where abusers will move on and find another target.