[DNSOP] Re: Is DELEXT too restrictive?
Philip Homburg <pch-dnsop-7@u-1.phicoh.com> Wed, 05 August 2026 16:10 UTC
Return-Path: <pch-b55F8B228@u-1.phicoh.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C7ABB1243372F for <dnsop@mail2.ietf.org>; Wed, 5 Aug 2026 09:10:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785946207; bh=VryQN3JXv0gMr5R1B1MViFvNGMF1KS2ZAPfkBeXLmuc=; h=To:Cc:Subject:From:References:In-reply-to:Date; b=EXHfexfa2yNNUvJiD9tN6rpb4WEnTMIc4IS4CVbrUg4RozSJ/qoBdhnpnnaJLwU9c uSRCTuWSoR2bhZtRmVo6xDH/JXp8VOKABT9zNCi402HdAtgA56RzbAnyrfrkpO0yi3 hfl2E1+dePNtWSLSDJma2uIuWSSl+4OubXIOYVJk=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=unavailable autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Zm6FXs4KUIdx for <dnsop@mail2.ietf.org>; Wed, 5 Aug 2026 09:10:07 -0700 (PDT)
Received: from stereo.hq.phicoh.net (stereo.hq.phicoh.net [IPv6:2a10:3781:2413:1:2a0:c9ff:fe9f:17a9]) (using TLSv1.2 with cipher ECDHE-ECDSA-CHACHA20-POLY1305 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 5B1CC124324FD for <dnsop@ietf.org>; Wed, 5 Aug 2026 09:02:37 -0700 (PDT)
Received: from stereo.hq.phicoh.net (localhost [::ffff:127.0.0.1]) by stereo.hq.phicoh.net with esmtp (TLS version=TLSv1.2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305) (Smail #158) id m1wre4h-0000OgC; Wed, 5 Aug 2026 18:02:35 +0200
Message-Id: <m1wre4h-0000OgC@stereo.hq.phicoh.net>
To: dnsop@ietf.org
From: Philip Homburg <pch-dnsop-7@u-1.phicoh.com>
Sender: pch-b55F8B228@u-1.phicoh.com
References: <m1wozxZ-0000OVC@stereo.hq.phicoh.net> <538EEAAD-9492-41A2-B412-13BC026F0719@dnss.ec> <m1wp2tq-0000O0C@stereo.hq.phicoh.net> <7EE41823-C911-486E-A49B-2D043DE02046@dnss.ec> <m1wp5jC-0000NrC@stereo.hq.phicoh.net> <ECEF8125-D62A-4109-B8B0-205A7C3200F5@dnss.ec> <m1wquvB-0000NwC@stereo.hq.phicoh.net> <1C0A23F3-92CF-46F7-8DFE-9F804A462D9E@dnss.ec> <m1wrETN-0000NzC@stereo.hq.phicoh.net> <4A0EC5E2-9C0A-4AE7-8959-D4FE9EC4503E@dnss.ec> <m1wrGW5-0000O0C@stereo.hq.phicoh.net> <EBC4FBC5-46DE-44A2-84E3-4BAB707C0B2F@dnss.ec>
In-reply-to: Your message of "Wed, 5 Aug 2026 14:07:43 +0100 ." <EBC4FBC5-46DE-44A2-84E3-4BAB707C0B2F@dnss.ec>
Date: Wed, 05 Aug 2026 18:02:34 +0200
Message-ID-Hash: XN6HBIYE4HSYIR25TSREY6AY6RHFLMPC
X-Message-ID-Hash: XN6HBIYE4HSYIR25TSREY6AY6RHFLMPC
X-MailFrom: pch-b55F8B228@u-1.phicoh.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Roy Arends <roy@dnss.ec>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: Is DELEXT too restrictive?
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/SLYiYk7nAjObh4gu58kX5jpw4LY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
> As a rough estimate, a single NS record adds about 22 octets, > depending on the target name and the available compression pointers. > An A record adds 16 octets, and an AAAA record adds 28 octets. This > gives approximately: 38 octets for an NS/A combination and 66 octets > for an NS/A/AAAA combination. > > A quick histogram of todays .com zone (roughly 165 million delegations) > gives the following distribution of name server counts per delegation: > NS count. Delegation 1 34939 2 > 128486053 3 10046108 4 22644556 > 5 1702108 6 539256 7 > 203418 8 1433091 9 3591 10 > 7488 11 838 12 14183 13 > 595 > > The largest group is therefore roughly 128 million delegations, or > 78%, with two name servers. For those delegations, retaining NS > records and any required IPv4 glue would add about 76 octets, or > about 132 octets where both IPv4 and IPv6 glue are present for each > name server. > > The next-largest group is roughly 22 million delegations, or 13%, > with four name servers. The corresponding increase would be about > 152 octets with IPv4 glue, or about 264 octets with both IPv4 and > IPv6 glue. > > Im not convinced that omitting NS and glue when DE=1 is a worthwhile > optimisation. It does not appear to provide a clear benefit to the > resolver, the operator, or the domain holder, while it introduces > different referral behaviour depending on whether DE is set. We have look at this in the context of ADoX. How big are multiple DELEG records if they also include TLSA and other TLS related params? Plus NSEC(3) and RRSIGs. This is an issue for TLDs and the root. If we push too many delegations over the edge then a lot of requests will be retried over TCP. Software doesn't care. So I'll leave it to operators to speak up.
- [DNSOP] Is DELEXT too restrictive? Roy Arends
- [DNSOP] Re: Is DELEXT too restrictive? Pieter Lexis
- [DNSOP] Re: Is DELEXT too restrictive? Michael Richardson
- [DNSOP] Re: Is DELEXT too restrictive? John Levine
- [DNSOP] Re: Is DELEXT too restrictive? Roy Arends
- [DNSOP] Re: Is DELEXT too restrictive? John R Levine
- [DNSOP] Re: Is DELEXT too restrictive? Petr Špaček
- [DNSOP] Re: Is DELEXT too restrictive? Philip Homburg
- [DNSOP] Re: Is DELEXT too restrictive? Peter Thomassen
- [DNSOP] Re: Is DELEXT too restrictive? Philip Homburg
- [DNSOP] Re: Is DELEXT too restrictive? Roy Arends
- [DNSOP] Re: Is DELEXT too restrictive? Philip Homburg
- [DNSOP] Re: Is DELEXT too restrictive? Roy Arends
- [DNSOP] Re: Is DELEXT too restrictive? Philip Homburg
- [DNSOP] Re: Is DELEXT too restrictive? Roy Arends
- [DNSOP] Re: Is DELEXT too restrictive? Philip Homburg
- [DNSOP] Re: Is DELEXT too restrictive? Roy Arends
- [DNSOP] Re: Is DELEXT too restrictive? Philip Homburg
- [DNSOP] Re: Is DELEXT too restrictive? Roy Arends
- [DNSOP] Re: Is DELEXT too restrictive? Philip Homburg
- [DNSOP] Re: Is DELEXT too restrictive? Roy Arends
- [DNSOP] Re: Is DELEXT too restrictive? Philip Homburg
- [DNSOP] Re: Is DELEXT too restrictive? John Levine
- [DNSOP] Re: Is DELEXT too restrictive? Philip Homburg
- [DNSOP] Re: Is DELEXT too restrictive? John Levine
- [DNSOP] Re: Is DELEXT too restrictive? Roy Arends
- [DNSOP] Re: Is DELEXT too restrictive? Philip Homburg
- [DNSOP] Re: Is DELEXT too restrictive? Roy Arends
- [DNSOP] Re: Is DELEXT too restrictive? Philip Homburg
- [DNSOP] Re: Is DELEXT too restrictive? John R Levine
- [DNSOP] Re: Is DELEXT too restrictive? Philip Homburg
- [DNSOP] Re: Is DELEXT too restrictive? Petr Špaček