[dns-operations] should recursors think there are only delegation data in tld name servers?

Peter Koch pk at DENIC.DE
Sun Mar 30 20:10:51 UTC 2014

On Fri, Mar 28, 2014 at 01:23:21PM +0800, ?????? wrote:
> dig @n.de.net 1s.de mx +dnssec
> and find that the mx record of 1s.de is from the n.de.net(,
> but it is not enough to make sure that from the .de zone. Maybe it the
> nameservers for the .de zone also serve for the 1s.de.

in theory, yes. But in that case there would be a zone cut, so both
an SOA RR or an NS RRSet.  Neither of those do exist.  Also, if you
look at the DNSSEC signature for the 1s.de. MX RR, you'll find "de."
as the signer's name.  Of course, this assumes you're just looking for
an existence proof. I'd not recommend to examine all this in a resolver
on a routine base.

> so it is clear for .de administrator to know the details.

And said entity shares these details through

	whois -h whois.denic.de. " -C iso8859-1 -T ace,dn 1s.de"


Peter Koch              |                           |         pk at DENIC.DE
DENIC eG                |                           |      +49 69 27235-0
Kaiserstraße 75-77      |                           |
60329 Frankfurt am Main |                           | http://www.DENIC.DE
Eingetr. Nr. 770 im Genossenschaftsregister Amtsgericht Frankfurt am Main
Vorstand: Helga Krüger, Carsten Schiefner, Dr. Jörg Schweiger
Vorsitzender des Aufsichtsrats: Thomas Keller

More information about the dns-operations mailing list