Re: [dnsext] Fwd: RFC 2308 & RFC 4035

Paul Vixie <vixie@isc.org> Sun, 27 February 2011 19:53 UTC

Return-Path: <vixie@isc.org>
X-Original-To: dnsext@core3.amsl.com
Delivered-To: dnsext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 4A92A3A67B5 for <dnsext@core3.amsl.com>; Sun, 27 Feb 2011 11:53:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6R3wL+zqeeHB for <dnsext@core3.amsl.com>; Sun, 27 Feb 2011 11:53:24 -0800 (PST)
Received: from nsa.vix.com (unknown [IPv6:2001:4f8:3:bb:230:48ff:fe5a:2f38]) by core3.amsl.com (Postfix) with ESMTP id 401873A67B0 for <dnsext@ietf.org>; Sun, 27 Feb 2011 11:53:24 -0800 (PST)
Received: from nsa.vix.com (localhost [127.0.0.1]) by nsa.vix.com (Postfix) with ESMTP id 9BC04A1058 for <dnsext@ietf.org>; Sun, 27 Feb 2011 19:54:20 +0000 (UTC) (envelope-from vixie@isc.org)
From: Paul Vixie <vixie@isc.org>
To: dnsext@ietf.org
In-Reply-To: Your message of "27 Feb 2011 18:30:42 GMT." <20110227183042.6563.qmail@joyce.lan>
References: <20110227183042.6563.qmail@joyce.lan>
X-Mailer: MH-E 8.2; nmh 1.2; XEmacs 21.4 (patch 22)
Date: Sun, 27 Feb 2011 19:54:20 +0000
Message-ID: <91393.1298836460@nsa.vix.com>
Subject: Re: [dnsext] Fwd: RFC 2308 & RFC 4035
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 27 Feb 2011 19:53:25 -0000

> Date: 27 Feb 2011 18:30:42 -0000
> From: John Levine <johnl@iecc.com>
> 
> ... If the zone is a DNSBL, there will be a whole lot of nxdomain
> queries, particularly in an IPv6 world where spamware hops to a new IP
> on every message.

i expect that most dnsbl's who evolve into ipv6 will also evolve a /64
"wildcard" strategy to cope with malware-controllable low order bits.

but i also agree that the importance of negative caching and synthetic
nxdomains is usually underestimated and will rise as the network grows.
(in an internet of things, most things searched for, will not exist,
whereas in the internet of today, most queries are for a small set of
not-existing objects.)