[dns-operations] Survey of How to Solving DNS Errors

Fred Morris m3047 at m3047.net
Thu Aug 15 20:40:40 UTC 2024


On Thu, 15 Aug 2024, Geoff Huston wrote:
>
> As to "what can you do"? there have been a couple of responses to this:
>

If you run Response Policy Zones (and BIND) you can partially mitigate the 
impact of search lists on this at the recursive resolver by defining 
things like *.com.example and *.com.example.com as "CNAME ." and ensuring 
qname-wait-recurse is set to "no". (Probably best to look at your own 
traffic with wireshark and identify the low hanging fruit.)

--

Fred Morris


More information about the dns-operations mailing list