[dns-operations] 答复: DNS forwarder behavior on response with cname

Stephane Bortzmeyer bortzmeyer at nic.fr
Fri Dec 7 15:45:17 UTC 2018

On Fri, Dec 07, 2018 at 10:44:05PM +0800,
 Davey Song <ljsong at biigroup.cn> wrote 
 a message of 56 lines which said:

> I'm wondering it is not necessary that the forwarder re-query the
> cname to double check the A record. It introduces another RTT
> delay.

Did you try with and without DNSSEC? I would say that paranoia
(double-checking) is good in general, but useless if the data is
DNSSEC-signed and if you validate.

More information about the dns-operations mailing list