--- Begin Message ---
> On 3 Dec 2025, at 11:01, Ondřej Surý <[email protected]> wrote:
>
> Ok, look at the NSEC3 proof that the servers give:
>
> vesdsjhfre0tap5h15gth2f925g1nj4c.realtor. 3600 IN NSEC3 1 1 0 - (
> VESDSJHFRE0TAP5H15GTH2F925G1NJ4C
> NS )
>
> The NSEC3 record points back to itself instead of to the next name and it is
> being properly rejected as invalid.
I wonder why the major public resolvers are not stricter. Sometimes I get tired
of customers claming that our
recursive DNS is wrong because Google resolves it. SIgh.
Borja.
signature.asc
Description: Message signed with OpenPGP
--- End Message ---
_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations