Generated: 2019-02-24T00:00:05Z -- 2019-02-26T16:18:47Z

Disclaimer:

The following report was generated automatically. Packet loss and network issues may have introduced false positives. Please verify the results before taking action.
You can report issues with this report to: marka@isc.org

Why you should care:

Most recursive resolvers now support EDNS. Lack of EDNS support in authoritative servers results in additional queries being made as the recursive servers need to retry with plain DNS and results in slower DNS resolution.

Not answering EDNS queries is particularly bad as that is indistingishable from packet loss.

Incorrect EDNS behaviour when presented with unknown EDNS versions and EDNS options can result in DNS resolution failures and/or DNSSEC validation failures.

Failure to run fully EDNS compliant nameservers will make it hard to deploy developments like DNS COOKIES which provides mitigation against DNS amplification attacks, off path spoofing resistance, RRL advoidance and excessive resource usage.

Codes

ok - test passed.
badvers - BADVERS returned.
badversion - expected EDNS version not found.
echoed - EDNS option echoed back.
formerr - FORMERR returned.
mbz - EDNS flags echoed back.
nodo - EDNS DO flag not echoed.
noopt - OPT record not found when expected. nosoa - SOA not found when expected.
notimp - NOTIMP returned.
refused - REFUSED returned.
servfail - SERVFAIL returned.
soa - SOA found when not expected.
status - expected status code not found.
toobig - UDP response bigger that advertised buffer size.
version - expected EDNS version not found.
reset - TCP connection reset.
timeout - lookup timed out.

Summary

Of servers that responded at all:
208879 of 211388 (98.81%) responded to a EDNS version 0 query
208761 of 211388 (98.76%) responded to a EDNS unknown option
208083 of 211388 (98.44%) responded to a EDNS unknown flags
207061 of 211388 (97.95%) responded to a EDNS version 1 query
207052 of 211388 (97.95%) responded to a EDNS unknown version and option

204242 of 211388 (96.62%) of nameservers support EDNS
169665 of 204242 (83.07%) EDNS capable servers are all ok
188718 of 204242 (92.40%) EDNS capable servers support unknown EDNS versions
183210 of 204242 (89.70%) EDNS capable servers support unknown EDNS options
201306 of 204242 (98.56%) EDNS capable servers support unknown EDNS flags
170415 of 204242 (83.44%) EDNS capable servers support unknown EDNS version and options
203380 of 204242 (99.58%) EDNS capable servers support DO=1

27506 of 204242 (13.47%) EDNS capable servers return a NSID option
21947 of 204242 (10.75%) EDNS capable servers return a EXPIRE option
27142 of 204242 (13.29%) EDNS capable servers return a SUBNET option
8602 of 204242 (4.21%) EDNS capable servers return a Server EDNS COOKIE option


© 2019 Internet Systems Consortium