Generated: 2019-03-24T00:00:00Z -- 2019-03-24T00:04:46Z

Disclaimer:

The following report was generated automatically. Packet loss and network issues may have introduced false positives. Please verify the results before taking action.
You can report issues with this report to: marka@isc.org

Why you should care:

Most recursive resolvers now support EDNS. Lack of EDNS support in authoritative servers results in additional queries being made as the recursive servers need to retry with plain DNS and results in slower DNS resolution.

Not answering EDNS queries is particularly bad as that is indistingishable from packet loss.

Incorrect EDNS behaviour when presented with unknown EDNS versions and EDNS options can result in DNS resolution failures and/or DNSSEC validation failures.

Failure to run fully EDNS compliant nameservers will make it hard to deploy developments like DNS COOKIES which provides mitigation against DNS amplification attacks, off path spoofing resistance, RRL advoidance and excessive resource usage.

Codes

ok - test passed.
badvers - BADVERS returned.
badversion - expected EDNS version not found.
echoed - EDNS option echoed back.
formerr - FORMERR returned.
mbz - EDNS flags echoed back.
nodo - EDNS DO flag not echoed.
noopt - OPT record not found when expected. nosoa - SOA not found when expected.
notimp - NOTIMP returned.
refused - REFUSED returned.
servfail - SERVFAIL returned.
soa - SOA found when not expected.
status - expected status code not found.
toobig - UDP response bigger that advertised buffer size.
version - expected EDNS version not found.
reset - TCP connection reset.
timeout - lookup timed out.

Summary

Of servers that responded at all:
6960 of 6978 (99.74%) responded to a EDNS version 0 query
6960 of 6978 (99.74%) responded to a EDNS unknown option
6956 of 6978 (99.68%) responded to a EDNS unknown flags
6955 of 6978 (99.67%) responded to a EDNS version 1 query
6957 of 6978 (99.70%) responded to a EDNS unknown version and option

6963 of 6978 (99.79%) of nameservers support EDNS
6944 of 6963 (99.73%) EDNS capable servers are all ok
6951 of 6963 (99.83%) EDNS capable servers support unknown EDNS versions
6961 of 6963 (99.97%) EDNS capable servers support unknown EDNS options
6958 of 6963 (99.93%) EDNS capable servers support unknown EDNS flags
6953 of 6963 (99.86%) EDNS capable servers support unknown EDNS version and options
6960 of 6963 (99.96%) EDNS capable servers support DO=1

3293 of 6963 (47.29%) EDNS capable servers return a NSID option
2151 of 6963 (30.89%) EDNS capable servers return a EXPIRE option
1820 of 6963 (26.14%) EDNS capable servers return a SUBNET option
659 of 6963 (9.46%) EDNS capable servers return a Server EDNS COOKIE option

Details:

No Addresses Records Found (6/13692)

cm. cm.cctld.authdns.ripe.net: no address records found (NXDOMAIN)
ni. ns.cr: no address records found
td. ns1.nic.td: no address records found (NXDOMAIN)
xn--fzc2c9e2c. ns3.ac.lk: no address records found (NXDOMAIN)
xn--xkc2al3hye2a. ns3.ac.lk: no address records found (NXDOMAIN)
xn--ygbi2ammx. idn.pnina.ps: no address records found (NXDOMAIN)

DNS lookup of zone SOA failed (65/13692)

(dig +noedns +norec soa $zone @$server)
expect: status: NOERROR
expect: SOA record

bb. @64.119.204.139 (ns2.barbadosdomain.net.): dns=servfail edns=servfail edns1=ok edns@512=servfail ednsopt=servfail edns1opt=ok do=servfail ednsflags=servfail optlist=servfail signed=servfail ednstcp=servfail
fj. @128.32.136.3 (adns1.berkeley.edu.): dns=refused edns=refused edns1=ok edns@512=refused ednsopt=refused edns1opt=ok do=refused ednsflags=refused optlist=refused signed=refused ednstcp=refused
fj. @2607:f140:ffff:fffe::3 (adns1.berkeley.edu.): dns=refused edns=refused edns1=ok edns@512=refused ednsopt=refused edns1opt=ok do=refused ednsflags=refused optlist=refused signed=refused ednstcp=refused
fj. @128.32.136.14 (adns2.berkeley.edu.): dns=refused edns=refused edns1=ok edns@512=refused ednsopt=refused edns1opt=ok do=refused ednsflags=refused optlist=refused signed=refused ednstcp=refused
fj. @2607:f140:ffff:fffe::e (adns2.berkeley.edu.): dns=refused edns=refused edns1=ok edns@512=refused ednsopt=refused edns1opt=ok do=refused ednsflags=refused optlist=refused signed=refused ednstcp=refused
ne. @194.51.3.49 (bow.rain.fr.): dns=refused edns=refused edns1=ok edns@512=refused ednsopt=refused edns1opt=ok do=refused ednsflags=refused optlist=refused signed=refused ednstcp=refused
ne. @196.216.168.45 (ns-ne.afrinic.net.): dns=servfail edns=servfail edns1=ok edns@512=servfail ednsopt=servfail edns1opt=ok do=servfail ednsflags=servfail optlist=servfail,nsid signed=servfail ednstcp=servfail
ne. @2001:43f8:120::45 (ns-ne.afrinic.net.): dns=servfail edns=servfail edns1=ok edns@512=servfail ednsopt=servfail edns1opt=ok do=servfail ednsflags=servfail optlist=servfail,nsid signed=servfail ednstcp=servfail
ni. @200.62.64.1 (ns.tmx.com.ni.): dns=noaa edns=noaa edns1=ok edns@512=noaa ednsopt=noaa edns1opt=ok do=noaa ednsflags=noaa optlist=noaa signed=noaa ednstcp=noaa
td. @196.216.168.31 (ns-td.afrinic.net.): dns=servfail edns=servfail edns1=ok edns@512=servfail ednsopt=servfail edns1opt=ok do=servfail ednsflags=servfail optlist=servfail,nsid signed=servfail ednstcp=servfail
td. @2001:43f8:120::31 (ns-td.afrinic.net.): dns=servfail edns=servfail edns1=ok edns@512=servfail ednsopt=servfail edns1opt=ok do=servfail ednsflags=servfail optlist=servfail,nsid signed=servfail ednstcp=servfail
xn--d1alf. @78.104.145.4 (dns-mk.univie.ac.at.): dns=refused edns=refused edns1=ok edns@512=refused ednsopt=refused edns1opt=ok do=refused ednsflags=refused optlist=refused,nsid,cookie,subnet signed=refused ednstcp=refused
xn--d1alf. @2001:628:453:bb::4 (dns-mk.univie.ac.at.): dns=refused edns=refused edns1=ok edns@512=refused ednsopt=refused edns1opt=ok do=refused ednsflags=refused optlist=refused,nsid,cookie,subnet signed=refused ednstcp=refused
xn--mgbai9azgqp6j. @175.107.192.11 (ns2.ntc.net.pk.): dns=servfail edns=servfail edns1=ok edns@512=servfail ednsopt=servfail edns1opt=ok do=servfail ednsflags=servfail optlist=servfail signed=servfail ednstcp=servfail

cd. @92.222.179.91 (ns-root-5.scpt-network.com.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
ci. @213.136.100.81 (ns.nic.ci.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
ci. @213.136.100.83 (ns1.nic.ci.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
fj. @144.120.8.10 (manu.usp.ac.fj.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
fj. @144.120.8.1 (teri.usp.ac.fj.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
gm. @196.49.1.87 (ns2.nic.gm.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
iq. @194.117.57.100 (ns1.cmc.iq.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
ir. @193.189.123.2 (a.nic.ir.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
jm. @200.9.115.2 (ns.utechjamaica.edu.jm.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
py. @200.33.111.1 (m.dns.py.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=ok,expire,cookie,subnet signed=timeout ednstcp=ok
tg. @104.243.39.7 (ns2.admin.net.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=connection-refused
tg. @188.165.33.42 (ns5.admin.net.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
ve. @150.188.228.4 (ns1.nic.ve.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
ve. @150.188.228.5 (ns2.nic.ve.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
ve. @190.202.128.43 (ns4.nic.ve.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
ve. @150.185.130.16 (azmodan.ula.ve.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--1qqw23a. @42.83.130.1 (ta.ngtld.cn.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--1qqw23a. @42.83.131.1 (tb.ngtld.cn.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--1qqw23a. @42.83.132.1 (tc.ngtld.cn.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--54b7fta0cc. @180.211.212.213 (bayanno.btcl.net.bd.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--55qx5d. @125.208.41.1 (b.ngtld.cn.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--55qx5d. @125.208.42.1 (c.ngtld.cn.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--fiqs8s. @125.208.36.1 (l.dns.cn.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--fiqz9s. @125.208.36.1 (l.dns.cn.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--io0a7i. @125.208.41.1 (b.ngtld.cn.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--io0a7i. @125.208.42.1 (c.ngtld.cn.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--j1amh. @212.1.66.247 (nsi.uanic.net.): dns=timeout edns=servfail edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=servfail
xn--j1amh. @195.123.1.7 (dns2.u-registry.net.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--mgba3a4f16a. @193.189.123.2 (a.nic.ir.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--mgbtx2b. @194.117.57.100 (ns1.cmc.iq.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--xhq521b. @42.83.130.1 (ta.ngtld.cn.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--xhq521b. @42.83.131.1 (tb.ngtld.cn.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--xhq521b. @42.83.132.1 (tc.ngtld.cn.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
zm. @196.46.192.26 (ns1.zamnet.zm.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout

bd. @2407:5000:88:5::3 (dns.bd.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
bd. @2407:5000:88:4::232 (surma.btcl.net.bd.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
bd. @2407:5000:88:4::231 (jamuna.btcl.net.bd.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
gr. @2001:678:7::4:10 (gr-m.ics.forth.gr.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
nr. @2403:f600:0:224::66 (ns0.cenpac.net.nr.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
nr. @2403:f600:0:225::9 (ns1.cenpac.net.nr.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
sr. @2803:a200:15:1001::2 (ns1.sr.net.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=connection-refused
sr. @2803:a200:15:1002::2 (ns2.sr.net.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=connection-refused
tg. @2001:41d0:8:5c79::3 (ns5.admin.net.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
ve. @2001:1338::2 (ns1.nic.ve.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
ve. @2001:1338::3 (ns2.nic.ve.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--54b7fta0cc. @2407:5000:88:2::3 (bayanno.btcl.net.bd.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--54b7fta0cc. @2407:5000:88:1::2 (ekushey.btcl.net.bd.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
xn--j1amh. @2607:5300:60:2e43::5 (dns1.u-registry.com.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout
ye. @2a02:2718:4::33 (ns1.yemen.net.ye.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=ok optlist=ok,expire signed=timeout ednstcp=ok
ye. @2a02:2718:4::34 (ns2.yemen.net.ye.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=ok optlist=ok,expire signed=timeout ednstcp=ok
zw. @2c0f:f758:0:13::42 (ns2.telone.co.zw.): dns=timeout edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout

EDNS not supported (1/13692)

(dig +edns +norec soa $zone @$server)
expect: status: NOERROR
expect: SOA record to be present
expect: OPT record to be present
expect: EDNS Version 0 in response
See RFC6891

If you do not wish to support EDNS you should still respond to the query. You can ignore the OPT record and respond to the query as if the OPT record was not present or you can respond with the error code FORMERR.

cm. @195.24.192.34 (lom.camnet.cm.): dns=ok edns=timeout edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=timeout do=timeout ednsflags=timeout optlist=timeout signed=timeout ednstcp=timeout

EDNS(0) version not handled correctly (4/13620)

(dig +edns +norec soa $zone @$server)
expect: status: NOERROR
expect: SOA record to be present
expect: OPT record to be present
expect: EDNS Version 0 in response
See RFC6891

cn. @66.198.183.65 (g.dns.cn.): dns=ok edns=timeout edns1=timeout edns@512=timeout ednsopt=ok edns1opt=ok do=timeout ednsflags=ok optlist=timeout signed=timeout ednstcp=ok
lb. @147.28.0.39 (rip.psg.com.): dns=ok edns=timeout edns1=ok edns@512=ok ednsopt=ok edns1opt=ok do=ok ednsflags=ok optlist=ok,expire,cookie,subnet signed=ok,yes ednstcp=ok
tg. @2406:d501::47e3:2a7c (ns4.admin.net.): dns=timeout edns=timeout edns1=ok edns@512=ok ednsopt=timeout edns1opt=ok do=timeout ednsflags=ok optlist=ok signed=timeout ednstcp=ok
tt. @200.33.111.1 (ns3.nic.mx.): dns=ok edns=timeout edns1=timeout edns@512=timeout ednsopt=ok edns1opt=timeout do=ok ednsflags=ok optlist=ok,expire,cookie,subnet signed=ok,yes ednstcp=ok

Unknown EDNS version not handled correctly (15/13620)

(dig +edns=1 +norec soa $zone @$server)
expect: status: BADVERS
expect: SOA record to NOT be present
expect: OPT record to be present
expect: EDNS Version 0 in response
See RFC6891, 6.1.3. OPT Record TTL Field Use

Timeouts on this test and edns1opt and possibly ednsflags indicate a badly configured firewall that is dropping packets just because the EDNS version is not zero. This breaks EDNS version negotiation. There is no known security flaw that will be triggered by allowing these packets through to the server.

cn. @203.119.25.1 (a.dns.cn.): dns=ok edns=ok edns1=timeout edns@512=ok ednsopt=ok edns1opt=timeout do=ok ednsflags=timeout optlist=ok signed=ok,yes ednstcp=ok
cn. @195.219.8.90 (f.dns.cn.): dns=ok edns=ok edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=ok do=ok ednsflags=timeout optlist=timeout signed=ok,yes ednstcp=ok
cn. @66.198.183.65 (g.dns.cn.): dns=ok edns=timeout edns1=timeout edns@512=timeout ednsopt=ok edns1opt=ok do=timeout ednsflags=ok optlist=timeout signed=timeout ednstcp=ok
ge. @212.72.130.11 (ns.nic.ge.): dns=ok edns=ok edns1=noerror,badversion,soa edns@512=ok ednsopt=ok edns1opt=noerror,badversion,soa do=ok ednsflags=ok optlist=ok,nsid signed=ok ednstcp=ok
kp. @175.45.176.15 (ns1.kptc.kp.): dns=ok edns=ok edns1=timeout edns@512=ok ednsopt=ok edns1opt=timeout do=ok ednsflags=timeout optlist=ok signed=ok ednstcp=ok
kp. @175.45.176.16 (ns2.kptc.kp.): dns=ok edns=ok edns1=timeout edns@512=ok ednsopt=ok edns1opt=timeout do=ok ednsflags=timeout optlist=ok signed=ok ednstcp=ok
lb. @193.188.128.14 (zeina.aub.edu.lb.): dns=ok edns=ok edns1=timeout edns@512=ok ednsopt=ok edns1opt=timeout do=ok ednsflags=timeout optlist=ok,expire,cookie,subnet signed=ok,yes ednstcp=ok
mp. @202.128.29.2 (ns1.nic.mp.): dns=ok edns=ok edns1=noerror,badversion,soa edns@512=ok ednsopt=ok edns1opt=noerror,badversion,soa do=ok ednsflags=ok optlist=ok,nsid signed=ok ednstcp=ok
mp. @202.128.29.135 (ns2.nic.mp.): dns=ok edns=ok edns1=noerror,badversion,soa edns@512=ok ednsopt=ok edns1opt=noerror,badversion,soa do=ok ednsflags=ok optlist=ok,nsid signed=ok ednstcp=ok
mp. @75.101.129.89 (ns3.nic.mp.): dns=ok edns=ok edns1=noerror,badversion,soa edns@512=ok ednsopt=ok edns1opt=noerror,badversion,soa do=ok ednsflags=ok optlist=ok,nsid signed=ok ednstcp=ok
mp. @75.101.133.101 (ns4.nic.mp.): dns=ok edns=ok edns1=noerror,badversion,soa edns@512=ok ednsopt=ok edns1opt=noerror,badversion,soa do=ok ednsflags=ok optlist=ok,nsid signed=ok ednstcp=ok
tt. @200.33.111.1 (ns3.nic.mx.): dns=ok edns=timeout edns1=timeout edns@512=timeout ednsopt=ok edns1opt=timeout do=ok ednsflags=ok optlist=ok,expire,cookie,subnet signed=ok,yes ednstcp=ok
uy. @200.33.111.1 (ns3.nic.mx.): dns=timeout edns=ok edns1=timeout edns@512=ok ednsopt=timeout edns1opt=ok do=ok ednsflags=ok optlist=ok,expire,cookie,subnet signed=ok,yes ednstcp=ok
vu. @202.80.32.9 (ns1-cctld.vunic.vu.): dns=ok edns=ok edns1=noerror,badversion,soa edns@512=ok ednsopt=ok edns1opt=noerror,badversion,soa do=ok ednsflags=ok optlist=ok,nsid signed=ok,yes ednstcp=ok
xn--fiqs8s. @195.219.8.91 (m.dns.cn.): dns=ok edns=ok edns1=timeout edns@512=ok ednsopt=ok edns1opt=ok do=ok ednsflags=ok optlist=timeout signed=ok,yes ednstcp=ok

OPT not included in truncated response (3/13620)

(dig +edns +dnssec +bufsize=512 +norec +ignore dnskey $zone @$server)
expect: status: NOERROR
expect: OPT record to be present
expect: UDP DNS message size to be less than or equal to 512 bytes
See RFC6891, 7. Transport Considerations

This test requires that there be a signed DNSKEY RRset at the zone apex to trigger truncation for the test to be valid. Errors may be under reported as a result.

timeout and notimp may be due to mishandling of DNSKEY by the nameserver.

cn. @195.219.8.90 (f.dns.cn.): dns=ok edns=ok edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=ok do=ok ednsflags=timeout optlist=timeout signed=ok,yes ednstcp=ok
cn. @66.198.183.65 (g.dns.cn.): dns=ok edns=timeout edns1=timeout edns@512=timeout ednsopt=ok edns1opt=ok do=timeout ednsflags=ok optlist=timeout signed=timeout ednstcp=ok
tt. @200.33.111.1 (ns3.nic.mx.): dns=ok edns=timeout edns1=timeout edns@512=timeout ednsopt=ok edns1opt=timeout do=ok ednsflags=ok optlist=ok,expire,cookie,subnet signed=ok,yes ednstcp=ok

Unknown EDNS options not correctly handled (3/13620)

(dig +ednsopt=100 +norec soa $zone @$server)
expect: status: NOERROR
expect: SOA record to be present
expect: OPT record to be present
expect: OPT=100 to not be present
See RFC6891, 6.1.2 Wire Format

cn. @195.219.8.90 (f.dns.cn.): dns=ok edns=ok edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=ok do=ok ednsflags=timeout optlist=timeout signed=ok,yes ednstcp=ok
tg. @2406:d501::47e3:2a7c (ns4.admin.net.): dns=timeout edns=timeout edns1=ok edns@512=ok ednsopt=timeout edns1opt=ok do=timeout ednsflags=ok optlist=ok signed=timeout ednstcp=ok
uy. @200.33.111.1 (ns3.nic.mx.): dns=timeout edns=ok edns1=timeout edns@512=ok ednsopt=timeout edns1opt=ok do=ok ednsflags=ok optlist=ok,expire,cookie,subnet signed=ok,yes ednstcp=ok

Unknown EDNS version + unknown EDNS options not correctly handled (12/13620)

(dig +ednsopt=100 +edns=1 +norec soa $zone @$server)
expect: status: BADVERS
expect: SOA record to NOT be present
expect: OPT record to be present
expect: OPT=100 to not be present
expect: EDNS Version 0 in response
See RFC6891

cn. @203.119.25.1 (a.dns.cn.): dns=ok edns=ok edns1=timeout edns@512=ok ednsopt=ok edns1opt=timeout do=ok ednsflags=timeout optlist=ok signed=ok,yes ednstcp=ok
cr. @200.33.111.1 (ns3.nic.mx.): dns=ok edns=ok edns1=ok edns@512=ok ednsopt=ok edns1opt=timeout do=ok ednsflags=ok optlist=ok,expire,cookie,subnet signed=ok,yes ednstcp=ok
ge. @212.72.130.11 (ns.nic.ge.): dns=ok edns=ok edns1=noerror,badversion,soa edns@512=ok ednsopt=ok edns1opt=noerror,badversion,soa do=ok ednsflags=ok optlist=ok,nsid signed=ok ednstcp=ok
kp. @175.45.176.15 (ns1.kptc.kp.): dns=ok edns=ok edns1=timeout edns@512=ok ednsopt=ok edns1opt=timeout do=ok ednsflags=timeout optlist=ok signed=ok ednstcp=ok
kp. @175.45.176.16 (ns2.kptc.kp.): dns=ok edns=ok edns1=timeout edns@512=ok ednsopt=ok edns1opt=timeout do=ok ednsflags=timeout optlist=ok signed=ok ednstcp=ok
lb. @193.188.128.14 (zeina.aub.edu.lb.): dns=ok edns=ok edns1=timeout edns@512=ok ednsopt=ok edns1opt=timeout do=ok ednsflags=timeout optlist=ok,expire,cookie,subnet signed=ok,yes ednstcp=ok
mp. @202.128.29.2 (ns1.nic.mp.): dns=ok edns=ok edns1=noerror,badversion,soa edns@512=ok ednsopt=ok edns1opt=noerror,badversion,soa do=ok ednsflags=ok optlist=ok,nsid signed=ok ednstcp=ok
mp. @202.128.29.135 (ns2.nic.mp.): dns=ok edns=ok edns1=noerror,badversion,soa edns@512=ok ednsopt=ok edns1opt=noerror,badversion,soa do=ok ednsflags=ok optlist=ok,nsid signed=ok ednstcp=ok
mp. @75.101.129.89 (ns3.nic.mp.): dns=ok edns=ok edns1=noerror,badversion,soa edns@512=ok ednsopt=ok edns1opt=noerror,badversion,soa do=ok ednsflags=ok optlist=ok,nsid signed=ok ednstcp=ok
mp. @75.101.133.101 (ns4.nic.mp.): dns=ok edns=ok edns1=noerror,badversion,soa edns@512=ok ednsopt=ok edns1opt=noerror,badversion,soa do=ok ednsflags=ok optlist=ok,nsid signed=ok ednstcp=ok
tt. @200.33.111.1 (ns3.nic.mx.): dns=ok edns=timeout edns1=timeout edns@512=timeout ednsopt=ok edns1opt=timeout do=ok ednsflags=ok optlist=ok,expire,cookie,subnet signed=ok,yes ednstcp=ok
vu. @202.80.32.9 (ns1-cctld.vunic.vu.): dns=ok edns=ok edns1=noerror,badversion,soa edns@512=ok ednsopt=ok edns1opt=noerror,badversion,soa do=ok ednsflags=ok optlist=ok,nsid signed=ok,yes ednstcp=ok

EDNS + DO=1 not handled correctly (3/13620)

(dig +dnssec +norec soa $zone @$server)
expect: status: NOERROR
expect: SOA record to be present
expect: OPT record to be present
expect: EDNS Version 0 in response
expect: DO flag in response if RRSIG is present in response
See RFC3225

Timeouts on this test (and signed) alone can indicate fragmentation issues at the sender. This would need to be confirmed with more testing.

cn. @66.198.183.65 (g.dns.cn.): dns=ok edns=timeout edns1=timeout edns@512=timeout ednsopt=ok edns1opt=ok do=timeout ednsflags=ok optlist=timeout signed=timeout ednstcp=ok
il. @2001:bf8:900:6::808b:22f0 (lookup.iucc.ac.il.): dns=ok edns=ok edns1=ok edns@512=ok ednsopt=ok edns1opt=ok do=timeout ednsflags=ok optlist=ok,expire,cookie,subnet signed=timeout ednstcp=ok
tg. @2406:d501::47e3:2a7c (ns4.admin.net.): dns=timeout edns=timeout edns1=ok edns@512=ok ednsopt=timeout edns1opt=ok do=timeout ednsflags=ok optlist=ok signed=timeout ednstcp=ok

Unknown EDNS flags are not correctly handled (5/13620)

(dig +ednsflags=0x80 +norec soa $zone @$server)
expect: status: NOERROR
expect: SOA record to be present
expect: OPT record to be present
expect: MBZ not to be present
expect: EDNS Version 0 in response
See RFC6891, 6.1.4 Flags

cn. @203.119.25.1 (a.dns.cn.): dns=ok edns=ok edns1=timeout edns@512=ok ednsopt=ok edns1opt=timeout do=ok ednsflags=timeout optlist=ok signed=ok,yes ednstcp=ok
cn. @195.219.8.90 (f.dns.cn.): dns=ok edns=ok edns1=timeout edns@512=timeout ednsopt=timeout edns1opt=ok do=ok ednsflags=timeout optlist=timeout signed=ok,yes ednstcp=ok
kp. @175.45.176.15 (ns1.kptc.kp.): dns=ok edns=ok edns1=timeout edns@512=ok ednsopt=ok edns1opt=timeout do=ok ednsflags=timeout optlist=ok signed=ok ednstcp=ok
kp. @175.45.176.16 (ns2.kptc.kp.): dns=ok edns=ok edns1=timeout edns@512=ok ednsopt=ok edns1opt=timeout do=ok ednsflags=timeout optlist=ok signed=ok ednstcp=ok
lb. @193.188.128.14 (zeina.aub.edu.lb.): dns=ok edns=ok edns1=timeout edns@512=ok ednsopt=ok edns1opt=timeout do=ok ednsflags=timeout optlist=ok,expire,cookie,subnet signed=ok,yes ednstcp=ok


© 2019 Internet Systems Consortium