Anand Buddhdev <anandb at ripe.net> wrote:
> These are VERY important points. Paul advocates RRL all the time, and it
> is a useful countermeasure. However, I would go one step further. I
> would say that name servers should simply NOT respond at all over UDP if
> they are queried for a zone they're not authoritative for.

I think this would make it unnecessarily hard to debug delegation
misconfigurations. It's fine to suppress reply traffic if you think
you are under attack, but ignoring legitimate queries isn't helpful.

The intro of Mark's draft is relevant...

