--- Begin Message ---
Was it for missing DS RRs? We saw something similar here when they were
doing an algorithm rollover and had to pull the DS RR from the TLD. Saw
a spike of traffic for DS RRs, but over UDP mostly, with some TCP. They
slowed down and stopped when the DS RR was replaced in the TLD.
Scott
On 17 Jun 2021, at 4:47, Randy Bush wrote:
trying to understand what we are seeing, and assume other are seeing
it
too.
tcp query flood for cctlds and sec.cctlds, could be others
being sent via popular open servers: goog, neustar, ...
O(100)qps or higher
randy
---
[email protected]
`gpg --locate-external-keys --auto-key-locate wkd [email protected]`
signatures are back, thanks to dmarc header butchery
_______________________________________________
dns-operations mailing list
[email protected]
https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Flists.dns-oarc.net%2Fmailman%2Flistinfo%2Fdns-operations&data=04%7C01%7Cscott.rose%40nist.gov%7C9c43447c41d9414287cb08d93171b9d2%7C2ab5d82fd8fa4797a93e054655c61dec%7C1%7C0%7C637595186785283927%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=KYMkqY6d%2BtUQknmQzOHgQwqch2cIDugM%2Fws%2Bm7jmwFI%3D&reserved=0
=================
Scott Rose, NIST/ITL
[email protected]
ph: +1-301-975-8439
GVoice: +1-571-249-3671
--- End Message ---
_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations