> Even with the slip values, I still feel this can open a wider window for other forms of attacks against a DNS zone. For example, the attacker spools with a legetimate IP and make a number of queries, thus RRL blocks that legetimate IP by mistake? -- Email/Jabber/Gtalk: pangj at riseup.net Free DNS Hosting with www.DNSbed.com