2 ms·
Note that running your own mirror of the root on the recursive nameserver(s) on your network will keep the traffic generated from these sorts of queries off the
by bewaretheirs 2y ago
Note that running your own mirror of the root on the recursive nameserver(s) on your network will keep the traffic generated from these sorts of queries off the rest of the internet.
If you're already running your own recursive resolver on reasonably up-to-date software it can be surprisingly easy to set this up; see rfc8806 for some config examples.
- lyu07282 2y agoIs there a use case for that? I mean other than that it's kinda cool
- bewaretheirs 2y agoPer rfc8806, because the data in the root zone has long TTL values, most queries to the root servers are for nonexistent top-level domains due to typos and search paths gone wrong, so in some sense it's community service to reduce useless traffic to the roots -- you do a single burst download of about 2MB daily instead of all of your query traffic. Other reasons why you might do it are covered in rfc8806 - slightly reduced latency on cold-cache DNS queries, added resilience against DoS attacks against root DNS servers.