[dns-operations] Seeing what looks like purpose-built CNAME loops

sthaug at nethelp.no sthaug at nethelp.no
Thu Apr 10 06:54:29 UTC 2025


I'm getting lots of queries to our resolvers for various names under
aws.blueapron.com, which all lead to

dcos-pub-east.aws.blueapron.com. 60 IN CNAME dcos-pub-east.aws.blueapron.com.

and thus an obvious CNAME loop, with our BIND resolvers logging messages
about "query iterations limit reached". So far so good. I'm wondering if
this is on purpose (trying for name server resource exhaustion) or some
kind of mistake. Anybody else seeing this?

Steinar Haug, AS 2116


More information about the dns-operations mailing list