We did not use an NTA, but we did flush our cache immediately once Slack had
fixed their problem. I think that’s the right balance of carrot and stick.
-Bill
> On Oct 2, 2021, at 7:30 AM, Mark Tinka <[email protected]> wrote:
>
> So, that wasn't fun, yesterday:
>
>
> https://lists.dns-oarc.net/pipermail/dns-operations/2021-September/021340.html
>
> We were also hit, given we run DNSSEC on our resolvers.
>
> Interesting some large open resolver operators use Negative TA's for this
> sort of thing. Not sure how this helps with the DNSSEC objective, but given
> the kind of pain mistakes like these can cause, I can see why they may lean
> on NTA's.
>
> Mark.