Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Some NXDomain entries that should be de-listed #1746

Open
vdukhovni opened this issue Apr 26, 2023 · 7 comments
Open

Some NXDomain entries that should be de-listed #1746

vdukhovni opened this issue Apr 26, 2023 · 7 comments
Labels
✔️DNS _psl Validated RFC 8553 Entries were present, matching PR# 🩺 pending-validation Something needs to be validated

Comments

@vdukhovni
Copy link

vdukhovni commented Apr 26, 2023

The suffixes below don't exist:

me.vu
blog.vu
dev.vu
us.kg
nyan.to
blog.gt
at.md
app.gp

[ Reproducer:

$ for zone in me.vu blog.vu dev.vu us.kg nyan.to blog.gt at.md app.gp; do dig +noall +comment +question -t soa $zone; done | grep -E 'HEADER|SOA'
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 5773
;me.vu.                         IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 24903
;blog.vu.                       IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 23178
;dev.vu.                                IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 22936
;us.kg.                         IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 45346
;nyan.to.                       IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 44082
;blog.gt.                       IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 9568
;at.md.                         IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 46026
;app.gp.                                IN      SOA

]

The below ServFail SOA lookups, and are therefore unlikely public suffixes:

to.md
us.ax
de.md
blog.kg
neko.am
es.ax
eu.ax
ch.tc
tv.kg

[ Reproducer:

$ for zone in to.md us.ax de.md blog.kg neko.am es.ax eu.ax ch.tc tv.kg; do dig +noall +comment +question -t soa $zone; done | grep -E 'HEADER|SOA'
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 11893
;to.md.                         IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 32794
;us.ax.                         IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 43243
;de.md.                         IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 15513
;blog.kg.                       IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 23054
;neko.am.                       IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 41333
;es.ax.                         IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 56421
;eu.ax.                         IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 6834
;ch.tc.                         IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 39922
;tv.kg.                         IN      SOA

]

@dnsguru
Copy link
Member

dnsguru commented Apr 27, 2023 via email

@vdukhovni
Copy link
Author

Commands to reproduce observations added.

@dnsguru
Copy link
Member

dnsguru commented May 4, 2023

Made small tweak to force use of 8.8.8.8 on the lookup to force a public resolver in replication

for zone in me.vu blog.vu dev.vu us.kg nyan.to blog.gt at.md app.gp; do dig +noall +comment +question -t soa $zone @8.8.8.8; done | grep -E 'HEADER|SOA'
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 62134
;me.vu.                         IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 44568
;blog.vu.                       IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 55489
;dev.vu.                                IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 36202
;us.kg.                         IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 65425
;nyan.to.                       IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 49255
;blog.gt.                       IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 39299
;at.md.                         IN      SOA
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 12597
;app.gp.                                IN      SOA

@dnsguru
Copy link
Member

dnsguru commented May 4, 2023

duplicated empty results - confirmed this from 4 different hosts on 4 different providers using 4 different public resolvers.

@dnsguru
Copy link
Member

dnsguru commented May 4, 2023

Hi community, please make a pull request for these changes

@dnsguru
Copy link
Member

dnsguru commented Jun 19, 2023

this appears to be tied to #1741

@dnsguru dnsguru added this to To-Do in List Add/Mod/Del via automation Jun 19, 2023
@dnsguru dnsguru added the 🩺 pending-validation Something needs to be validated label Jun 19, 2023
@dnsguru
Copy link
Member

dnsguru commented Jul 5, 2023

#1755 tied to this;

@dnsguru dnsguru linked a pull request Jul 5, 2023 that will close this issue
10 tasks
@groundcat groundcat mentioned this issue Sep 6, 2023
@dnsguru dnsguru added the ✔️DNS _psl Validated RFC 8553 Entries were present, matching PR# label Oct 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
✔️DNS _psl Validated RFC 8553 Entries were present, matching PR# 🩺 pending-validation Something needs to be validated
Projects
Development

Successfully merging a pull request may close this issue.

2 participants