Paul Hoffman <paul.hoffman at vpnc.org> wrote:
> It sounds like a bad configuration for RRL at f-root, given the replies
> below that they are unique queries (which would make sense from a
> caching resolver).

I don't think it is that bad. If you fail to ratelimit because all the
queries are different then attackers have a trivial bypass.

