[DNSOP] Re: Deployment tests for "probe.resolver.arpa"

Ben Schwartz <bemasc@meta.com> Wed, 21 May 2025 01:54 UTC

Return-Path: <prvs=1236dedf22=bemasc@meta.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 7469F2AFE83D for <dnsop@mail2.ietf.org>; Tue, 20 May 2025 18:54:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.793
X-Spam-Level:
X-Spam-Status: No, score=-2.793 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=meta.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EgRuvKfxBI4N for <dnsop@mail2.ietf.org>; Tue, 20 May 2025 18:54:28 -0700 (PDT)
Received: from mx0b-00082601.pphosted.com (mx0b-00082601.pphosted.com [67.231.153.30]) by mail2.ietf.org (Postfix) with ESMTP id CD03A2AFE834 for <dnsop@ietf.org>; Tue, 20 May 2025 18:54:28 -0700 (PDT)
Received: from pps.filterd (m0109332.ppops.net [127.0.0.1]) by mx0a-00082601.pphosted.com (8.18.1.2/8.18.1.2) with ESMTP id 54L1QMiZ028443; Tue, 20 May 2025 18:54:27 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=meta.com; h= content-type:date:from:in-reply-to:message-id:mime-version :references:subject:to; s=s2048-2021-q4; bh=i8Tc9kV4p+azFQueD/dc jq7HFP+5153G4WN67w41tf0=; b=Wdwl1Dgt0PafJobd72nIy/t+K7gQaJQg/DLc xIHlchEX0ULnvSW8eYQ/RHTtWNaKPqOJ9n72h3QZbQvBiu/Yaq1Gwxmb/DfHijlC ZHcOF5jH9+5K16q9QDGP2gYzsNBj87LbodA+adEgoC4ldh6M0oJl4QAEMwzeaIZ/ ktdr5X/0rbMnnIxvHh/+V4QAohkgjfga1oFMuafwsHuv4Ay6xPaeN0WySPTizwoV GFF9tQXyWrczhlY+xaGqzSm/lU6QjkOiHK8yYA87a2rnWah4jSTThW+r0gq9GJ3k i1hbluEMqvf5dRSEBM+jo4FtLgdDa5pEUHGYkYaJ2VTBS+s4sQ==
Received: from nam11-co1-obe.outbound.protection.outlook.com (mail-co1nam11lp2169.outbound.protection.outlook.com [104.47.56.169]) by mx0a-00082601.pphosted.com (PPS) with ESMTPS id 46rwf9v48x-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 20 May 2025 18:54:27 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=XO6KGvzdz2v44XVKZQRpkYDBywCya03RtxSVDIj5aNhubTaQ2YTf+WN9RDM6HRq9ZZE7LaQtGwKvf8yES4YF1bwcJsFy8g2kY+ys2hEf9sluhyPH69H343HNU7H50ajbrSz4zgl9kDYvojoW6uPfuetaqsvTE0kHYH0JVh6/ap9/tLWtn+cySkNi3MAgbDuMNZbMZ1ZyvAbbmajkei4MIGwECsge1/rl3A5Nka7PSaxAGO2lKCXPlpOGg/zVkfWmDXr+lmidbYss6/fIdq/sfFLZRpWMrP6UsvcfEawDoA8Hdw+RHEjbz5dDSlJyD7CN2e/oWGIOQGt1o1RHS7dYbA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=i8Tc9kV4p+azFQueD/dcjq7HFP+5153G4WN67w41tf0=; b=m1IRyRAlx4UiOnA4Ig+4JdfSqMGw41mpbo6wIEax5oiOMAzqWJ4Hjn+2nqyyZdjme+T+Eg5Z7ZO4q8KSyexkYC+MSbQchr4a6Z/jjNuxsTkZ+7WG5ZK2/M8nCBkXgAkIvjjb18ysSI0iyTRIyv4Ck4uCu9/0yXO+ZWGBe/OP7k83UKfyRdvyHNrnWm+2GvMHx9RDLPGQqdoJRDBHezcGLwfaJWOZPODEuobNpZvtWtrYtrFoRyu6GErKsm9ciRapH3inp6CVUkrWufdXTA72iVFqrz+JZ7S5Vm/p0K+X7RMQy1ml4FMe4Gz+/7cgvMrTMSdiFBUtSVG0HFh1YP4ezg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=meta.com; dmarc=pass action=none header.from=meta.com; dkim=pass header.d=meta.com; arc=none
Received: from SA1PR15MB4370.namprd15.prod.outlook.com (2603:10b6:806:191::8) by SN7PR15MB4190.namprd15.prod.outlook.com (2603:10b6:806:10c::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8746.30; Wed, 21 May 2025 01:54:25 +0000
Received: from SA1PR15MB4370.namprd15.prod.outlook.com ([fe80::b6dd:72cc:243a:babb]) by SA1PR15MB4370.namprd15.prod.outlook.com ([fe80::b6dd:72cc:243a:babb%6]) with mapi id 15.20.8769.019; Wed, 21 May 2025 01:54:25 +0000
From: Ben Schwartz <bemasc@meta.com>
To: Michael De Roover <ietf@nixmagic.com>, "dnsop@ietf.org" <dnsop@ietf.org>
Thread-Topic: [DNSOP] Re: Deployment tests for "probe.resolver.arpa"
Thread-Index: AQHbyOKy9F1pQQrR00KAPMY1iwjIW7PcHOsAgAAzBD8=
Date: Wed, 21 May 2025 01:54:25 +0000
Message-ID: <SA1PR15MB43703D41CFC32A24930D7FBDB39EA@SA1PR15MB4370.namprd15.prod.outlook.com>
References: <SA1PR15MB4370984AE1604666FFA470E2B39CA@SA1PR15MB4370.namprd15.prod.outlook.com> <1975082.FsBFY9rHsf@workstation.vm.ideapad.lan>
In-Reply-To: <1975082.FsBFY9rHsf@workstation.vm.ideapad.lan>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SA1PR15MB4370:EE_|SN7PR15MB4190:EE_
x-ms-office365-filtering-correlation-id: 2609d3b1-708e-4a93-a8ed-08dd980a69f9
x-fb-source: Internal
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|10070799003|366016|376014|1800799024|38070700018|7053199007|8096899003;
x-microsoft-antispam-message-info: RRQv2a0KKpj+LLBHdFPffItA1MTffsLItZAlEM+t27OIqv/9HYC6+POf6HOvWAZcBLpkVNBx15Gui56aybM+zPmyaFUX0Ga3doXbHnGrgk+Pf26zmjUuJ5xj6/lM1R3EOThVuVMncIOwSbwuIxEECmK0+HuZDlFCddh08A/UMpFSoY7QJ1Ci/zihtv+Yhy6VNCo6E2/Z+NW25plVwROIt10U94bpFP1eePQ5VHbKVF3bmjtT8es1Heu9GpUEdS3Rs7Z9IVewGHjNfmlW1xMDBb395KHK69k6S0OQwmD7LL3kg8dYCR7C6dfuCgTHe5/cyvuRyoj7sU2kt2PDLmQDMDglQ+cMt95xPB6O6ldpvUii2wGU2mQPq113yhUAaL8wWEKlhcXSmn49wm7yd8Dgyxh2AkPUMLCO7lmB1mdSa2eMAS0UAql7Wonp5oaGDO7uWLJ4Tt3zyQ/6bHLhzcjjTdewkKVkiAia2VBNzDOzPP4s8Dw3oZo+e+X5ArQe45hGe7e9KnlGjQDN4I4PxgyAzCMS2h1XYavbjKt+0NeQ+4dRs8Enp9K23ELNuUZZNbBqweTZRB6P2vNYtxtHrxXb2LZhXfS7ULPw0zih1mIU/ssSwWhLn1X9suLF4vLs2YGZGWpQSRa/xhko3V6KRzW8pWgY8/yM3OsmAKa8YpWtR5U8zkgs1BFfmcD0GKCPelMP9foT0BuzSGWpcasd4ewtzOkdQtBL9SHqYlgKsDTNUvn3Gw9uif+huXtoY1k93f5LOgKDA2Gbu5wf59XnvW1XkAHW1nGwWZmruaLe1qFjCN+UfbFobbKXFQHOvPx1evi+7/U5TKqMq2nbxiGVRBP88P9QdaHsrnRRE6D7KI8aQAUVtLrqMWTMGjGxZKQG+sgzERMESxaN7LQOk8th4VX4pbp9VBoEp2jE/h6AEwUg2tDJQdl/hKMx0puMWTVt26/E1T+/NvAEQgIQM5KcLQKF6AhYLUXWk+qetv6Hfxm8k8jAxM+WVd7rH8moOD4ozPtwUmpEK4aYtpozhiZjgQdj5gvPCb8AlEFCZ89AGsUXxxbvvrWpBLlACs1+JGGvzbyt/qr43QzrUhxY8SjP0M+QGGJcvnEm2aDmKStOBh7Hs9pE/9Ek/PZQxV9vQgfU8+Fv8BStbCrU23ZCFeraRfoPGRUGsf0cnaZESjLwp80G31aRg7+YZbajt2oDlrzDrRVSlZaRf/g1oPMzbNBaTBoRvHEwUfdyC8Ns/It9wvxsaDWeSdtZUHb1+x/0WsitcqaQBywIgEpskmGoHPTXsqAXxNiE67hZEJnDP8grjSiiamtMSkl8qDasIBmfSwOs46MJJ6zLKphp7Lt7dSYrrcbYNk2uoEcZ50hYM0wNF/qTPQ8Fc17Ba86dCrYIeaSPP2Re79WxLvIiaq1DE8xHUD/34nkfH19NjYn+rvAHLVFttR0=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:SA1PR15MB4370.namprd15.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(10070799003)(366016)(376014)(1800799024)(38070700018)(7053199007)(8096899003);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 97PGgk1PDIeUj8fQiAv3Rjrf2TP0QYGWFlRlMV9/DW2OBxTdD3ZSfQdgQ3B0v/oRzcbq35yAcEKsutbt5LZpByNXWXmVl+Gv6smNy2d1V3VMlV4SRltkYWdpCz2zjyNpRMc2m23h2dgtRHYs2zHD2O3KIYtrtK+aeD4etdUjrMpQs8ITu5BBQQTf/4mieoW/MKi8+yr61vGOaacOdd3n9+ST56IlGDTPMYhS+rSNHpxcsJTiquq404d43BG7gU7+fKqOx43XhYqDYpEf8Kdoq43s5ouvOjYMfJvlXV1EN3zfxTpzRrKpG+kr5KMUsbM8MQEesN+dGURfWPep6EtwKH4V6Zmfpv7aehH1f18gP/M++4/wjLZaShqzIo/QxyGMl6d6TeG73ryj9+me57r2v5zDdmHvFkk97VdUcC1YGoj8I1qSnP3c9R7tEm+n5LHbk3AvCnvC+0RMgej05fJMMo3yJsAdylOG/+Ai5TkCfSC7TpEmhaY3NjOTdUMuP9tuG3OJsyQY5cPcYYhzZjVhqFaE9LpnYaBdtpg/9/ojp6De+JJ64vhTfPCsc86SCK08IQXncf7S1PO9m53qhiS0FAbSCuIgeBMOGLHB0HYBHy9d/9l2T9LLLuNK1XsSmO1zfFjo/jZPpL0mE17g9+yhCPt1szkSIFo+5LpC6jrKqG+L3Cae1LjSB7BxKC1Fb+vU47Dx/P3huINi83SetvhtFBSCj2U2hCmn7W6RJIVyC0V1/fuxxaVau7o+HusTT6TpWB4fWkdT9zBF+FVjeJNaLcHnlFvCeHZmKcNT7wQr/D+5yBAc7/TEvBkwSx0DpZozFrUQ21uHkuClQtY9pXck202Oq6VyZvWnA9YMLIZKmor0H8irRGhsWaIRF3UvlWq0MJH6tWBVzUfYsOvv8IIIB18MfXtuuzUQhM2bDSAmBMxtM6dwHrUamElaEzSCNM7fe7EMq353HypTvdi9wqOLll5xOkFJ3Io8NH460TOe5ppih6a7GNqcbx6MGjXuhBDt3CD57V5ySZ5bTrV7c4jo27cmT+yoDznhwcKcFnDcuackKI50Gj1GtGptmJNNl0K28hrQiYX0wFfJKvkj43RQlPv9dxbmucJlF9vl6VdHu6TgRU/HjB2jkQfMoCH66wtMkDOZ/K0PuRtGt/QZkAf1uV0f7fM/gF2WIAC9YFRBzqjWLk2znBskMiQ+bs7Ol2AhyD8HUS2ZsOzXfOjpEmKhM/Q1iwponZM3q57jvmI4TinUsXzrm15+HXBh2SzLxD2b8ishDbv/ctgzmc64tDbdKpgQ1YGWrNmtCcBhmpLYD9zOGCPSjJPm8/wn6Kvsbh6qpHUq/h60/K+byji6ab0+96wvSiPO6h3CUhCIVboyEA21Wd0ZHs5m5rIUZkCpHabeguhGAxdWJDQNgz0RpOexW/GU5OXoydPnsKfF9o7PteEVHfhsnjXhCefZdMvWztO5lDTKGub+dT9+Q1VKgh+U7rqxCl3tOqE+b2t3HfQbtGfsgmavu8X9g8OoP7SAmHkbKMVRsTD8+mXU+qX3EoiHpDKFC5rkY4SUfmARMncGq9tiWAEaS4gb3N/Bbsgqub2ZXDCshA3j9/h9ll/u5nyWFhldQhRHvit3OVTgRoMofEU=
Content-Type: multipart/alternative; boundary="_000_SA1PR15MB43703D41CFC32A24930D7FBDB39EASA1PR15MB4370namp_"
MIME-Version: 1.0
X-OriginatorOrg: meta.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SA1PR15MB4370.namprd15.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 2609d3b1-708e-4a93-a8ed-08dd980a69f9
X-MS-Exchange-CrossTenant-originalarrivaltime: 21 May 2025 01:54:25.1335 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 8ae927fe-1255-47a7-a2af-5f3a069daaa2
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: O621w2kzNV5cPlsUkGL04zNkp0CrGRwOrN/JwXrlJEBLL0fw53U8CSGtqukoqpOC
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN7PR15MB4190
X-Proofpoint-Spam-Details-Enc: AW1haW4tMjUwNTIxMDAxNyBTYWx0ZWRfX+O37XWHDa8uc M+9iFg399ozOZHRALfdAhERzxohpYjSHYoZLK8El/A7fxb2YQLJIIMW0q1olEzdWrE0fEl76cMn Jsurxn/opwAuG+hQqDGdyAoyR4BewVTSir+bQVkkrtrM3HZPgHdV7VCaftsJdFUMqPz/n0PfOF7 yUwJAwMBvloeuic+i1jU/SdbQ2xmzT3cHj3AkF9HgvICTx7upKjI2FIGXJ3goAApFTttDDbduQZ 8a5uR1UePzwhNYDTsdlE4tE43FtPGNmga44Aj0Jlr5XzwmWWlU/ehbNZKsKvNlc3BjflKlQbA+6 HsCxp+GyQsJr3H+LRRU+GzWZ+xrSEkbwSZ4TELTiopqatB++ym0T7c6IxM7QiQ6xVSpRpSXQdWv q8N7RVvL8YOWf+UoGHXy5spaZfVeASO7ONOMhiBq0gQdxSFvedq7VtJKYwCagJlBSn2gFHoc
X-Authority-Analysis: v=2.4 cv=AMMSjJaD c=1 sm=1 tr=0 ts=682d3253 cx=c_pps a=MPHjzrODTC1L994aNYq1fw==:117 a=lCpzRmAYbLLaTzLvsPZ7Mbvzbb8=:19 a=wKuvFiaSGQ0qltdbU6+NXLB8nM8=:19 a=Ol13hO9ccFRV9qXi2t6ftBPywas=:19 a=xqWC_Br6kY4A:10 a=dt9VzEwgFbYA:10 a=n8i27M1mAAAA:8 a=npP5kB74AAAA:8 a=rAJKne17LQx7Y0RlhAcA:9 a=wPNLvfGTeEIA:10 a=obwJh_r1iXdwhWwv:21 a=frz4AuCg-hUA:10 a=_W_S_7VecoQA:10 a=G78r-VH0ULvY7SNRRd5L:22
X-Proofpoint-ORIG-GUID: 43arQ3-xnu74vtDkeM00T8jIftnA1FwY
X-Proofpoint-GUID: 43arQ3-xnu74vtDkeM00T8jIftnA1FwY
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1099,Hydra:6.0.736,FMLib:17.12.80.40 definitions=2025-05-21_01,2025-05-20_03,2025-03-28_01
Message-ID-Hash: XHTYS7YRY2CSZGU5XMJFQO4PAE7C7VBE
X-Message-ID-Hash: XHTYS7YRY2CSZGU5XMJFQO4PAE7C7VBE
X-MailFrom: prvs=1236dedf22=bemasc@meta.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: Deployment tests for "probe.resolver.arpa"
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/ciPRwdIUGPzG74RNXR5kijniVWs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

________________________________
From: Michael De Roover <ietf@nixmagic.com>

...

> Hi Ben, Puneet, John, DNSOP.

> I've yet to look into the document and repository to form a conclusive opinion
> on it, but so far I'm really liking what I'm seeing.

Great!

...

> From what I understand about the draft so far, it seems that this would be a
> vendor-neutral convergence point to do these connectivity checks against.

No, that is not the idea.  The idea is that when performing connectivity checks against any recursive resolver, you should use this arbitrary QNAME, not some other arbitrary QNAME.

> I
> like that idea, especially if it is also jointly operated by existing high-
> reliability service providers. There's no denying that Google's, Meta's, and
> Quad9's availability is among the best in the industry.

This draft is not proposing anything like that.  You're welcome to write a proposal like that, but I think it would be separate from this draft.

...

> Additionally, I'm curious about what this might imply for OS implementations
> of this feature, given the impressive lineup of authors. One of the gripes
> I've had with Android in particular, is that it's had a pretty hard dependency
> on Google's Public DNS for quite some time now. While at the network
> management level, it does allow DNS servers to be advertised by DHCP, that is
> not forwarded into applications like e.g. Termux by the Bionic C library.'

That information is exposed to apps via the Android Java API: https://developer.android.com/reference/android/net/LinkProperties#getDnsServers()

> This
> means that 8.8.8.8 is assumed until changed manually inside such application.

This sounds like a choice attributable to the Termux developers.

--Ben