2 ms·
To be perfectly fair, the list of DNSSEC cock-ups is staggering. .nz ccTLD was taken down, IIRC, for 4 days after a bad KSK rollover just last year. I’ve seen p
by api_or_ipa 3y ago
To be perfectly fair, the list of DNSSEC cock-ups is staggering. .nz ccTLD was taken down, IIRC, for 4 days after a bad KSK rollover just last year. I’ve seen prominent registrars with ‘automated’ DNSSEC fail to upload correct NSEC and RRSIGs. It’s not uncommon to see .gov domains go down because of DNSSEC. You’d think all these entities should get it right, but they don’t. Probably why many major tech domains such as google.com don’t use DNSSEC.
But to your point, using a ‘off-brand’ can really hurt sometimes. `.af` might be a cute marketing tactic, but it’s actually Afghanistan, and the Taliban play by a different rulebook. I believe it was `gay.af` that found that out the hard way. Tons of other stories.