Tony Finch dot at dotat.at
Thu Nov 17 14:28:46 UTC 2016

Mark Andrews <marka at isc.org> wrote:
> Note also the SOA MNAME is only supposed to be used if it matches
> a NS record name.  Updates are supposed to be able to go to any
> nameserver for the zone.

Hmf. There are a couple of problems with this model:

It doesn't seem reasonable to expect an UPDATE to work if it is sent
to an off-site secondary run by a third party.

If you have a hidden master setup, it would be nice to get UPDATEs to go
to a dedicated UPDATE server, completely separate from the read-only
publication slaves, and probably also separate from the hidden master.

