--- Begin Message ---

> On 3 Dec 2025, at 11:01, Ondřej Surý <[email protected]> wrote:
> 
> Ok, look at the NSEC3 proof that the servers give:
> 
> vesdsjhfre0tap5h15gth2f925g1nj4c.realtor. 3600 IN NSEC3 1 1 0 - (
>                                VESDSJHFRE0TAP5H15GTH2F925G1NJ4C
>                                NS )
> 
> The NSEC3 record points back to itself instead of to the next name and it is 
> being properly rejected as invalid.

I wonder why the major public resolvers are not stricter. Sometimes I get tired 
of customers claming that our
recursive DNS is wrong because Google resolves it. SIgh.





Borja.

Attachment: signature.asc
Description: Message signed with OpenPGP


--- End Message ---
_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations

Reply via email to