Promoting DNSSEC to nay-sayers

sthaug at sthaug at
Fri Sep 29 11:33:42 UTC 2017

> > May I please ask this audience for advice on if and how to promote
> > DNSSEC to those who nay-say?
> There's a really neat DNSSEC-related improvement on the way: RFC 8198
> negative answer synthesis. This should greatly reduce the amount of junk
> queries to the root name servers (and other parts of the namespace too).
> Should be particularly good for mail servers that deal with amazing
> amounts of toxic waste.

Which begs the question: Should we expect Joe Average DNS Administrator
to care about the amount of junk queries to the root name servers?

Note that I'm not against DNSSEC, I just think that this may not be the
best argument in favor.

Steinar Haug, Nethelp consulting, sthaug at

More information about the bind-workers mailing list