Cloudflare reverse DNS SERVFAIL, normal?

David opendak at shaw.ca
Mon Aug 29 23:54:53 UTC 2016


On 2016-08-29 5:47 PM, Chris Adams wrote:
> Once upon a time, Mark Andrews <marka at isc.org> said:
>> The following is general and is not directed at Cloudflare.  I know
>> some people don't think errors in the reverse DNS are not critical
>> but if you are delegated a zone it is your responsablity to ensure
>> your servers are correctly serving that zone regardless of where
>> it is in the DNS heirarchy.  Failure to do that causes additional
>> work for recursive servers.  If you don't want to serve a zone then
>> remove the delegation.
>
> You are assuming that an authoritative server operator has some way to
> know all the zones people delegate to their servers, and remove such
> delegations if they don't want to handle them.  That is a wrong
> assumption.
>

Even more generally is that your authoritative server should respond to 
anything it is asked with an appropriate answer. Dropping/filtering can 
lead to bad situations.



More information about the NANOG mailing list