> Upon receipt of a POST request containing the source and target parameters, the receiver SHOULD verify the parameters (see Request Verification below) and then SHOULD queue and process the request asynchronously, to prevent DoS attacks.
https://www.w3.org/TR/2017/REC-webmention-20170112/
Though, probably, this won't happen in practice. So better to be careful.