Been there recently. Rate limit on nginx and anti-syn flood on pf solved it.

I'm being hit with 300 req/s 24/7 from hundreds of thousands of unique IP's from residential proxies. I can't rate limit any further without hurting the real users.

Yeah, IP-based rate limits are nearly ineffective these days.