Limit recursion to trusted netblocks and customers.  Do not permit
your name servers to provide recursion for the world.  If you do,
you will contribute to one of these attacks.

        <recursion is a fundamental DNS design feature,
         restricting it to "walled gardens" cripples its usefullness>

I don't really think that preventing every Tom, Dick, and Harry from using my nameserver to look up domains I'm not authoritative for is going to cripple DNS. They really should have their own severs that do that for them, or they should use the ones provided to them by their ISP.

Reply via email to