> > One mitigation approach is to blackhole the domains using local zones. > > That?s not much of a mitigation. Not having open resolvers would be > mitigation.
Not having open resolvers is good - but unfortunately doesn't help against misbehaving clients (e.g. small home routers with DNS proxies open to queries from the WAN side). Steinar Haug, Nethelp consulting, sth...@nethelp.no
_______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users