You need to respond to ANY's if you want mail delivery to your domains.  There are some popular mail servers out there that don't send MX requests, only ANY to find out where to deliver email to.  

Rate limiting is the way to go and stops it dead.  Whilst you still get lots of requests, they drop off quicker and your outbound traffic is eliminated.  It's worked very well for us and the CN ANY attacks going on for the last few months.

On Jun 10, 2012, at 3:45 PM, Jim Reid wrote:

> And why pick on my name server which has never done anyone any harm?

They're just looking for ANY records, there's no rhyme or reason to it.  They're spoofing the IP address of the target they're attacking - they're using your server for reflection/amplification.

Do you really need to respond to ANY queries - especially when your servers are being abused?

