[dns-operations] ok, DNS RRL (rate limits) are officially, seriously, cool

Phil Regnauld regnauld at nsrc.org
Mon Jun 25 08:28:41 UTC 2012



On 25/06/2012, at 09.40, Klaus Darilion <klaus.mailinglists at pernau.at> wrote:

> I would expect that outgoing traffic is constant. Maybe, in this case also legitimate queries are blocked (false positive)

That's assuming all other clients are behaving properly in the first place, could be a non negligible number of malware generating this background noise. Their existence might be revealed by rate limitation. 

But yes, it's worth digging. 


More information about the dns-operations mailing list