fire-eyes wrote:
On my small server I am seeing a sudden inrush of requests to named like tihs.
Of particular intrest is _domainkey. A quick google search didn't really
explain why I am seeing so much of this, it's been going on almost
continuously for 20 minutes.
So, anyone recognize this stuff?
Well, this "stuff", as you call it, is just normal DNS queries - but
more of them than you usually get, as you noted.
One or two per second is nothing to worry about, and would not be
considered a DoS attack even if you were on a 56K link...
The _domainkey queries are experimental, or from people who already
implement SPF and Yahoo's scheme for it.
That was 10 seconds of Google, by the way ;-)
If you really want to know what is happening, you need to log DNS
requests and replies.
Then you can see what information is exchanged, and lookup where they
come from.
J
--
[email protected] mailing list