[dns-operations] query dropping vs. returning nxdomain

Duane Wessels wessels at packet-pushers.com
Wed Mar 15 18:30:53 UTC 2006


> Would it generally be considered poor form to drop queries you do
> not want to answer? Perhaps not only queries that would return
> NXDOMAIN, but also queries that maybe administratively you do not
> wish to answer.

You might find that it has the opposite effect.  We know from both
simulations and real traffic that when resolvers don't get answers
back from important authoritiatve servers (ie, roots and tlds),
they tend to panic and become more aggressive in their retransmissions.

Duane W.



More information about the dns-operations mailing list