Re: [dns-operations] Interesting messages in our logs

2014-11-02 Thread Keith Mitchell
If you didn't already check it out, you may find this presentation at our last workshop adds some background: https://indico.dns-oarc.net//contributionDisplay.py?contribId=37&sessionId=3&confId=20 Keith On 11/02/2014 08:52 AM, Lyle Giese wrote: > Just to flush out the details here, in case anyo

Re: [dns-operations] Interesting messages in our logs

2014-11-02 Thread Lyle Giese
Just to flush out the details here, in case anyone is wondering. We have a small number of domains that are DNSSEC signed, but those under attack are not signed. In the past two days, I am seeing RRL kicking in heavily for queries for host names or subdomains in the form: .example.com From