[dns-operations] Force TCP for external queries to Open Resolvers?

Stephane Bortzmeyer bortzmeyer at nic.fr
Sun Mar 31 16:47:27 UTC 2013


On Sun, Mar 31, 2013 at 12:27:05PM -0400,
 Paul Wouters <paul at nohats.ca> wrote 
 a message of 18 lines which said:

> Not all open resolvers are run by brainless admins..... And I
> believe open resolvers are crucial to the open nature of the
> internet.

There are two categories of open resolvers. The vast majority is made
of unmanaged boxes or boxes managed by a clueless and irresponsible
admin.

A very small minority is run by people who know what they are doing
(everyone has his favorite example, let me mention OARC's ODVR
<https://www.dns-oarc.net/oarc/services/odvr>). That's why RFC 5358 is
careful in its wording and does not say that resolvers MUST NOT be
recursive.




More information about the dns-operations mailing list