[dns-operations] Software that refuses an answer by QTYPE if it comes over plain UDP?

Tony Finch dot at dotat.at
Wed Mar 16 11:45:31 UTC 2016

Dave Warren <davew at hireahit.com> wrote:
> Yet CloudFlare went further, disabling them over TCP as well. I'm a little
> disappointed by this as they're certainly a timesaver when troubleshooting
> (although I suppose that doesn't make any difference to them)

Hmm. Thinking about it further, you're probably right that from the point
of view of avoiding bad effects from abuse, it's OK to give a full reply
to ANY over TCP. I've amended my BIND patch to do that. (link below)

Cloudflare have two reasons for minimal ANY responses: to quell abusive
clients, and to avoid query amplification in the back-end of their DNS
implementation. Their servers are on-demand DNSSEC signing proxies, and
it's hard for them to assemble an ANY response. So they don't want to do
it over TCP almost as much as over UDP.


