[dns-operations] MX record scanning

Carlos Vicente cvicente.lists at gmail.com
Mon May 9 16:06:06 UTC 2011

Dear list,

In the last week or so I've noticed a significant increase in queries per
second on one of our authoritative servers, which happens to be secondary
for a number of TLDs. A quick inspection of the traffic patterns seems to
indicate an MX record scanning process with no distinguishable origin (I'm
guessing a bot net). I was wondering if anyone else was experiencing this
and if they had any thoughts they'd want to share.

I'm attaching a screenshot of the DSC graph that shows the increase in the
last few days.


Carlos Vicente
University of Oregon
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20110509/372a303a/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: uoregn-dsc-qps-graph.png
Type: image/png
Size: 5420 bytes
Desc: not available
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20110509/372a303a/attachment.png>

More information about the dns-operations mailing list