> Robert Edmonds <mailto:[email protected]>
> Wednesday, November 26, 2014 4:59 PM
>
> What about specifying *no* nameservers? That is, delegating the domain
> name to a nonexistent nameserver name within an intentionally empty
> sacrificial zone with a lengthy negative TTL.

experience and observation say that even with a lengthy negative ttl,
there will be an awful lot of queries sent to the closest enclosing NS
RRset for that nameserver name. there would also be a large volume of
syslog traffic worldwide concerning this misconfiguration.

something like AS112 would be best -- a real address that can be sunk or
dunked by anyone.

-- 
Paul Vixie
_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to