A little more, from Comcast SF bay area: Its responding to large EDNS MTUs just fine for me:
dig +dnssec any . @m.root-servers.net works (4096B MTU) but with a 512B MTU (no EDNS) it doesn't because there is no working TCP: dig any . @m.root-servers.net ;; Truncated, retrying in TCP mode. ;; Connection to 2001:dc3::35#53(2001:dc3::35) for . failed: host unreachable. ;; communications error to 202.12.27.33#53: connection reset And its not an IPv6 error, nor specific to the ANY query for the instance I'm connecting to, because: dig +tcp NS . @202.12.27.33 ;; communications error to 202.12.27.33#53: connection reset Traceroute for me (comcast, SF bay area): 8 pos-0-0-0-0-pe01.11greatoaks.ca.ibone.comcast.net (68.86.86.54) 18.236 ms 19.293 ms 18.971 ms 9 xe-9-3-0-0.sjc10.ip4.tinet.net (213.200.80.165) 18.936 ms 17.631 ms 18.901 ms 10 xe-0-0-0.par20.ip4.tinet.net (89.149.187.165) 188.885 ms 170.598 ms xe-1-0-0.par20.ip4.tinet.net (89.149.187.169) 187.812 ms 11 213.200.76.38 (213.200.76.38) 174.631 ms 171.042 ms 170.649 ms 12 * 213.200.76.38 (213.200.76.38) 171.488 ms !X * 13 * 213.200.76.38 (213.200.76.38) 174.952 ms !X * 14 213.200.76.38 (213.200.76.38) 172.172 ms !X * 175.036 ms !X My net has no filtering that I know of on DNS, either UDP or TCP: http://n1.netalyzr.icsi.berkeley.edu/restore/id=43ca253f-32397-7e23ee37-14c3-4026-9f6b/rd _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop