> Nice to see you on the List :)
Yeah, finally started migrating :-)

> The First question will be who does the fragmenting and what kind of
> fragment are we talking about.
Well, the problem is not so much the fact that the packet is fragmented,
but that the DF bit is set on both fragments.
> In any case I don't think that the Packaet Size of a DNS should be much
> bigger then.
Unfortunately in the age of EDNS the packet size can be up to 4096
bytes, and with DNSSEC (as in this case) the replies tend to be in the
kilobyte range.

