> Florian Weimer <mailto:f...@deneb.enyo.de>
> Friday, March 06, 2015 12:03 PM
>
> Some resolvers will ask all authoritative servers for the domain when
> they receive a NOTIMP response. Others will not cache the resulting
> SERVFAIL response.
>
> So unless this is intended as some way to punish resolver operators
> who have clients sending ANY queries, this is probably not such a good
> idea.

to put the punishment where it belongs, i suggest that NOERROR/ANCOUNT=0
is a correct response to ANY from a non-trusted source.

-- 
Paul Vixie
_______________________________________________
dns-operations mailing list
dns-operations@lists.dns-oarc.net
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to