[dns-operations] Org responses not deterministic

George Barwood george.barwood at blueyonder.co.uk
Wed Jul 1 08:25:43 UTC 2009

dig dnskey org @a0.org.afilias-nst.info +dnssec

gives a response with size 1334 bytes about 3 times out of 4, but a 1723 byte response 1 time out of 4,
the difference being the addition of org NS RRset and glue.

I don't say this is wrong, but find it slightly surprising, and wondered if it is deliberate.

Given that UDP responses greater than the ethernet MTU ~1500 bytes are liable to be lost,
I think the shorter response is preferable.

( http://ops.ietf.org/lists/namedroppers/namedroppers.2009/msg01513.html )

