[dns-operations] DNS cookies in a mixed resolver anycast environment

sthaug at nethelp.no sthaug at nethelp.no
Fri May 31 16:01:47 UTC 2019

> During the period, the oldest encounter and one of the most critical was a 17 year old Authoritative Servers running Windows DNS. They have now fixed this, it took around 6 months for them. I believe they were not alone. 
> Just because 99.9% looks OK in statistics, does not mean that it really work in real life scenarios. Businesses and Government organs still think that "DNS is old and easy service, we do not need to update". 
> Even if and when we reach out, there are instances that does not listen and still think it is our fault. 

And there are authors of DNS software out there who have no plans to
implement EDNS (not even minimalist correct answers) - read the mail
thread at


and weep. No, it's not really about PowerDNS.

Steinar Haug, AS2116

