[dns-operations] A lot of CNAME queries for domain ?

Tony Finch dot at dotat.at
Thu Jul 5 18:33:38 UTC 2012

Mohamed Lrhazi <ml623 at georgetown.edu> wrote:

> Yeah... I did read somewhere recently that some SMTP RFC does say the
> mail server should query for the CNAME record, but only if MX record was
> not found....

No, that isn't right. It's never necessary for software to query for a
CNAME since the name server will return the CNAME in response to queries
for other types. See RFC 1034 section 3.6.2.

You might be thinking of the canonicalization requirement in RFC 1123
section 5.2.2, but this has been obsolete since the 1990s and isn't part
of modern SMTP.

See also http://fanf.livejournal.com/122220.html

> This is bigger issue because I just found out my DNS server is
> generating a malformed packet, as a response to these
> specific queries... 

I'm not getting any responses to CNAME queries from ns1 or ns3, and ns2
returns a malformed response.

I have heard of some resolvers going insane when they can't get a
response, which might be why you are getting so many queries - but that
doesn't explain why they were making CNAME queries in the first place.

