Promoting DNSSEC to nay-sayers

>> > There's a really neat DNSSEC-related improvement on the way: RFC 8198
>> > negative answer synthesis. This should greatly reduce the amount of junk
>> > queries to the root name servers (and other parts of the namespace too).
>> > Should be particularly good for mail servers that deal with amazing
>> > amounts of toxic waste.
>> Which begs the question: Should we expect Joe Average DNS Administrator
>> to care about the amount of junk queries to the root name servers?
> You win from lower latency responses and wasting less RAM on negative
> cache entries.

You also win (IMO, the biggest win) if you are authoritative and have
signed your zone -- if cuts down on the pain you feel from (many of
the current) DoS attacks.


