[DNSOP] Re: ordering of RRSets in the answer section of a DNS response

Joe Abley <jabley@strandkip.nl> Thu, 15 January 2026 11:41 UTC

Return-Path: <jabley@strandkip.nl>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C6616A8060D6 for <dnsop@mail2.ietf.org>; Thu, 15 Jan 2026 03:41:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.799
X-Spam-Level:
X-Spam-Status: No, score=-2.799 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=strandkip.nl
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cimxlCgIhB06 for <dnsop@mail2.ietf.org>; Thu, 15 Jan 2026 03:41:33 -0800 (PST)
Received: from outbound.soverin.net (outbound.soverin.net [185.233.34.18]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 68646A8060C8 for <dnsop@ietf.org>; Thu, 15 Jan 2026 03:41:33 -0800 (PST)
Received: from smtp.soverin.net (unknown [10.10.4.100]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by outbound.soverin.net (Postfix) with ESMTPS id 4dsLfh38Bsz7l; Thu, 15 Jan 2026 11:41:32 +0000 (UTC)
Received: from smtp.soverin.net (smtp.soverin.net [10.10.4.100]) by soverin.net (Postfix) with ESMTPSA id 4dsLfh08MRzJY; Thu, 15 Jan 2026 11:41:32 +0000 (UTC)
Authentication-Results: smtp.soverin.net; dkim=pass (2048-bit key; unprotected) header.d=strandkip.nl header.i=@strandkip.nl header.a=rsa-sha256 header.s=soverin1 header.b=IIvo/rVb; dkim-atps=neutral
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=strandkip.nl; s=soverin1; t=1768477292; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=L2wQDoiubWB7F2Ekwv5JkukCq57kGh6dfYqf3nybT3o=; b=IIvo/rVbQs2syFD5l/oWZoEwOgu//ujUu8zaSPReIxJ+bc3OvnhxU0YFyyB1UfVApOLYDW 9YIZuE5negztZzLf3VUSLoz/5NniOMAzkb70GrCkogxN575qhdK+H0ClsSOXvqjYL7tHq+ 68SW00aFpMYy/MlZgONmd1nVaW/O1LhmINJ+x7lswSLCDgIeoT549nu6Rw2PW/KL9cpEG0 b7E5pSYX7uSUtDa87NGqkyaxrmJTv2bqn2sJSNfn60nbQ2xUPeQOoc2Zuj8mqwWAHVfbmV ZL65Iw4DxXy/ivPcCaQ6jnIyT7tibRJ58DeF1AIMsOeRDqOsZ9YrFgvA5DWMVw==
X-CMAE-Score: 0
X-CM-Envelope: MS4xfEOyeS3Z7Z+7xTfpQoxl98pvqR6TxOoMRsR5BjyF6BILOBAoyL/slzHddb9UmvT5Mjp/ODmXFdf42YPYeVphpEJPSMspfV97iaUkC4FD6rzEAgNiplTB X733SMmMvXiBPD1Tu6aiwqyn2h/rN/OeuFBSQva/a94lJtmJyc22tAcjv6cKqaVRK3aRX0fd/U68HAXDK/TBheEukmZ2v+FejKv91WBJkEAVYl8inquKMej6 y8r4niSwItjhAUDrXdInoQ==
X-CM-Analysis: v=2.4 cv=d/oPyQjE c=1 sm=1 tr=0 ts=6968d26c a=eRI1dRrTBRd5R8BO3924WQ==:117 a=eRI1dRrTBRd5R8BO3924WQ==:17 a=kj9zAlcOel0A:10 a=48vgC7mUAAAA:8 a=FHVFsUYG02zTPsq_0EwA:9 a=CjuIK1q_8ugA:10
X-Soverin-Id: 019bc175-f5e0-7c3f-8d2c-9177d913f4ea
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
From: Joe Abley <jabley@strandkip.nl>
Mime-Version: 1.0 (1.0)
Date: Thu, 15 Jan 2026 12:41:21 +0100
Message-Id: <8DDA7DF4-85D7-41BC-A39B-0C125474EDD9@strandkip.nl>
References: <102fa8f6-4c04-4c5c-b49d-c31ff812817d@nic.cz>
In-Reply-To: <102fa8f6-4c04-4c5c-b49d-c31ff812817d@nic.cz>
To: Libor Peltan <libor.peltan=40nic.cz@dmarc.ietf.org>
X-Spampanel-Class: ham
Message-ID-Hash: GPPMLEOJEDVLQRVCGJR7YJM5BPG5B2H2
X-Message-ID-Hash: GPPMLEOJEDVLQRVCGJR7YJM5BPG5B2H2
X-MailFrom: jabley@strandkip.nl
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: dnsop <dnsop@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: ordering of RRSets in the answer section of a DNS response
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/gmorkeBxYvitSrdLs-qLumWH5Rg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

On 15 Jan 2026, at 11:52, Libor Peltan <libor.peltan=40nic.cz@dmarc.ietf.org> wrote:

> I think that you are motivated by the scale how the broken clients are wide-spread, and how crippled upgrade policies prevent upgrading them in reasonable time. However, writing and publishing an RFC also doesn't happen in a short time.

Yes, that's totally the motivation. 

I think of this as an investment in the future; if we can avoid future disasters (even small ones) by making a decision now, I think the return on investment is reasonable. 

If we had done this in 2015 there's at least a chance that 1.1.1.1 would have had a test to prevent the release that caused things to break last week. If we do this in 2025 perhaps there's some DNS service operator in 2035 that will quietly thank us :-)

> If we however decide to go ahead with this document, I'd like to have it more limited in scope (perhaps only recursive-to-stub responses, maybe only CNAME and DNAME, no effect on DNSSEC) and clearly explaining (with examples! of correct and incorrect responses) what are the consequences and what aren't, for example to SVCB alias-form, non-standard ALIAS records etc etc. The current wording is so general that I can't event say if some response complies or not.

I am fine with all of that and I agree it's important that the advice be well-scoped and actionable. 

Thanks,


Joe