[dns-operations] Mass deletion of .tw sub-domains?

Viktor Dukhovni ietf-dane at dukhovni.org
Tue Sep 24 16:18:10 UTC 2019


> On Sep 24, 2019, at 5:37 AM, Florian Weimer <fw at deneb.enyo.de> wrote:
> 
> I did some checks on a few of those.  WHOIS is still populated, and
> they seem to share name servers.  The names may be random, but they
> seem to have *something* in common.

Thanks.  I spot-checked four, and all were registered one
year ago, and are now expiring.  The nameservers I saw were:

      ns4.dnsdun.com
      ns4.dnsdun.net
      ns1.dns.com
      ns2.dns.com
      ns1.dnsfang.com
      ns2.dnsfang.com
      v1s1.xundns.com
      v1s2.xundns.com

The first two had the same registrant, all four registrants
had mainland China addresses.  So something unusual started
a year ago, ... but probably not worth pursuing further if
not immediately clear what...

-- 
	Viktor.



More information about the dns-operations mailing list