Paul Hoffman writes:
>    However, implementations MUST NOT send stale data if they have received
>    any answer from an authoritative server.

I personally strongly disagree with this.

ServFail is a signal from the authoritative operator that something is
amiss, and is in practical terms is not really distinguishable from
being unable to reach them. It's not just a "funny answer".  If the
resolver was previously able to get good answers for the same query
but is now getting the server declaring things are whack, I don't see
how passing through the ServFail helps anything, and it harms the
intended resiliency of this whole endeavour.

DNSOP mailing list

Reply via email to