On Nov 6, 2012, at 4:40 AM, Feng He wrote:

> 于 2012-11-6 17:08, Steven Carr 写道:
>> They all expect you to use their own custom DNS management tools for
>> managing the domain and expect that you only have it hosted with them,
>> I'm not even sure some of the providers would allow you to create
>> additional NS records so yes there could be problems in that the glue
>> would not match the NS returned by one of the providers, so it would
>> appear that some of the NS are stealth.
> That's great point. I totally agree with it.

Or, if they're not in-baliwick it may require additional queries to prime things on recursive servers.

DNSSEC of course addresses object-level security issues with authoritative servers.


