[dns-operations] DNSSEC and qmail

Tony Finch dot at dotat.at
Thu Oct 8 11:53:07 UTC 2009


On Thu, 8 Oct 2009, Roy Arends wrote:

> > It's asking for cam.ac.uk. IN ANY when trying to canonicalize the
> > recipient domain.
>
> I don't understand.

The old SMTP specs require that all domains were canonicalized, i.e. that
CNAMEs were resolved to their final target domains. qmail still does this
even though nowadays no-one else cares if a domain is canonical or not.
(I think that was also true when qmail was written.)

> > > Second, I'd expect qmail to talk to resolver. resolvers generally trip the
> > > response to stubs to fit a 512 udp message.
> >
> > They do?
>
> roy$ dig +norec cam.ac.uk any
>
> ; <<>> DiG 9.4.3-P3 <<>> cam.ac.uk any
[...]
> ;; MSG SIZE  rcvd: 451

I get

;; Truncated, retrying in TCP mode.

; <<>> DiG 9.4.2-P2 <<>> +norec any cam.ac.uk.
[ snip loads ]

;; Query time: 5 msec
;; SERVER: 127.0.0.1#53(127.0.0.1)
;; WHEN: Thu Oct  8 11:51:14 2009
;; MSG SIZE  rcvd: 1315

Tony.
-- 
f.anthony.n.finch  <dot at dotat.at>  http://dotat.at/
GERMAN BIGHT HUMBER: SOUTHWEST 5 TO 7. MODERATE OR ROUGH. SQUALLY SHOWERS.
MODERATE OR GOOD.



More information about the dns-operations mailing list