Stephane Bortzmeyer <bortzmeyer at nic.fr> wrote:
> What about forcing TCP for ANY requests only?

I think it's wrong to focus on ANY queries: restricting them just
encourages the attackers to move on to another query type. For a domain
with DNSSEC you get almost as much data in return to an MX query - 2KB vs
1.5KB for cam.ac.uk.

