Greetings, The NXDOMAIN redirection features in BIND 9 - "type redirect" zones, and the "nxdomain-redirect" option - were introduced in BIND 9.8 and 9.11 respectively. They each trigger an extra lookup from an alternate namespace allowing an NXDOMAIN response to be replaced with a positive answer, unless the NXDOMAIN originates from a DNSSEC-signed domain. In that case, the rewritten answer would fail to validate, so the NXDOMAIN is passed through unchanged.
At the time these features were first implemented, DNSSEC-signed domains and validating resolvers were still quite rare. As they have become more and more common, NXDOMAIN redirection has become less and less effective. We believe it is now only used infrequently in production environments. (Please let us know if this is incorrect.) Aside from its limited utility, NXDOMAIN redirection introduces complexity into the query processing logic that has led to security bugs in the past, and may lead to more in the future. Consequently, per ISC's deprecation policy, I am notifying the mailing list that we intend to end support for "type redirect" zones and for the "nxdomain-redirect" option in named. Our plan is to mark them as deprecated in BIND 9.20, and remove them completely as of BIND 9.22. Comments, questions and feedback are welcome. -- Evan Hunt -- [email protected] Internet Systems Consortium, Inc. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list.

