[dns-operations] open resolver versio.bind responses

Vernon Schryver vjs at rhyolite.com
Tue Apr 16 15:58:32 UTC 2013


> From: Jared Mauch <jared at puck.nether.net>

> Check out the breakdown.html page  ...

    2013-04-14 results

    34030764 servers responded to our udp/53 probe
    914175 servers responded from a different IP than probed
    27773382 gave the 'correct' answer to my A? for the DNS name queried.
    13721271 responded from a source port other than udp/53
    29571967 responses had recursion-available bit set.
    2827206 returned REFUSED

What was heard from the 3.4 million servers that responded with neither
the A RR nor REFUSED?  The 2.8 million that REFUSED are significantly
fewer than those mysterious 3.4 million, not to mention the 27 million
functional open resolvers or the 29.5 million ostensibly open resolvers.

In other words https://www.google.com/search?q=sisyphus seems
relevant.  I don't mean to suggest that the effort is not worthwhile.
The work is valuable, but realism forces us to acknowledge some
implications.  One is that there is no hope in "outreach."


Vernon Schryver    vjs at rhyolite.com



More information about the dns-operations mailing list