[dns-operations] NSATC DNS oddities last week (affecting hotmail, msn etc)

Matt Larson mlarson at verisign.com
Fri Aug 3 12:52:47 UTC 2007


On Fri, 03 Aug 2007, bert hubert wrote:
> 2) It has been suggested that PowerDNS invalidate an NS record from its
> cache if it is not responsive, and refetch from higher up.

I can already hear my colleague, Piet Barber, screaming,
"Nooooooooooo!!!" :-)

A Reasonably Popular Implementation did this and we saw truly amazing
traffic storms to the .com/.net servers when a popular zone would go
offline (and hundreds of thousands of iterative resolvers would
requery the .com servers to check the delegation).

We documented this behavior and gave reasoning why it's not the best
choice in RFC 4697, section 2.1.

Matt




More information about the dns-operations mailing list