Best practice on TCP replies for ANY queries

Tony Finch dot at
Thu Dec 12 13:29:45 UTC 2013

Anurag Bhatia <me at> wrote:
> Now I see presence of some (legitimate) DNS forwarders and hence I don't
> wish to limit queries.

You are going to have to change your mind about this one. Open recursive
resolvers are a really bad idea, unless you can afford a lot of time and
cleverness to manage the abuse. Get your users to choose a more
appropriate name server, and restrict your name server to your local

