Three major types of #DNS failures are timeouts, latency, and DNS NXDOMAIN errors. Observability tools often can overlook these areas - so do they matter? Well, it depends how many services you would like to break.

Assuming your answer is ‘none’ – head over to our blog to learn how to master effective DNS observability and keep your system running failure-free:

https://t.ly/RycwR

#NXDOMAIN #opensource #devops #tech #IT #observability #SRE #coroot #mongodb

This one is a pretty long read, and it goes into details of observed #NXDOMAIN patterns with a bias towards the #DNS landscape in #China. I did not expect to see so much leakage of non-public TLDs, but I guess that - despite the bias towards Chinese networks- it probably looks similar in other parts of the world.

After reading this pretty long article, I was still somewhat feeling that it should have gone deeper into query flood phenomena which might cause spikes in NXDOMAIN responses.

No matter what, a well-spent 10 minutes on educating yourself on things that are often not illuminated on one of the #Internet core protocols.

Have a nice weekend, everyone!

#rootservers #infosec

Deep Dive into NXDOMAIN Data in China

The Domain Name System (DNS) is an essential protocol in the architecture of today's Internet. It routinely translates domain names into IP addresses and also often handles a multitude of invalid queries. These include requests for non-existent domain names, termed NXDOMAIN. A high volume of such invalid queries can adversely

奇安信 X 实验室

Apparently all .tv domains registered through Sarek Oy (sarek.fi; or #Njalla, which uses them) are currently disabled by the .tv registry (turnon.tv / godaddy). No details are known and domain owners were not notified. This affects a few piracy sites, but also any other unrelated .tv domains, unfortunately including my jomo.tv domain. Piracy related .tv domains using a different registrar are not affected.

#tv #turnontv #godaddy #sarek #sarekfi #sarekoy #dns #serverhold #whois #piracy #nxdomain

@gabboman if any of #CloudFlare #DNS appears in the DNS query, the entire recursion stops, hence it will return the #NXDOMAIN and the fact the domain is hosted at a CF server, also add a undesirable log entry at CF

Whom queried what... also data that are sold
Akkoma

@dangillmor already #dotZIP & #dotMOV are basically exclusively used for #Malware & #Phishing to the point that I'd not be surprised if bir corpirations will just rollout #hostfile|s that redirect #zip & #mov - domains onto some warning site or flat out yeet aka. #NXDOMAIN them...

@lattera
Do you know where those two commands NXDOMAIN and NOERROR are documented.

Unfortunately, the manual via `man hosts' has no mention of them.

#hosts #etcHosts #hostsFile #NXDomain #NOError

DNS-Techniker arbeiten wohl noch. #NXDOMAIN #rC3

Der Hostname im #PTR-Record meiner #IPv4-Adresse bei #Fiber7 löst seit heute mittag nicht mehr auf. (#NXDOMAIN). Das ist doof, wenn man an einer /etc/hosts.allow mit Hostnamen oder Domains drin vorbei muss.

Ist das sonst noch jemand aufgefallen?

Now, #DNS extended errors (today, only a very small choice of possibles errors, compare with HTTP with all its status codes https://www.flickr.com/photos/girliemac/sets/72157628409467125/ ). #IETF100 #SERVFAIL #NXDOMAIN #REFUSED
HTTP Status Cats

HTTP Status Cats API : http.cat (Thanks, Rogério Vicente!) Tweet me at @girlie_mac if you have ideas or pics recommendations! (Updated: I am receiving overwhelming amount of comments/suggestions! Thank you so much and sorry for not replying to all of you!) HTTP Status Codes desc: en.wikipedia.org/wiki/List_of_HTTP_status_codes