Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Another reason to prefer _dnslink.domain: prevention of plausible future dns amplification attacks #29

Open
sixcorners opened this issue May 8, 2022 · 0 comments

Comments

@sixcorners
Copy link

sixcorners commented May 8, 2022

A dns amplification attack is a way to multiply the amount of bytes you are sending to a denial of service target. If there are domains with large records on them an attacker can send requests for these records to be responded to the victim to amplify their attack.
I think the main concern right now are other types of records or responses like ANY or AXFR... but it could be in the future that if everyone put their TXT records directly on the domain root you could end up with some sites with giant dns responses.

I don't know if it is worth adding this to the faq about _dnslink.domain. https://dnslink.io/#why-use-dnslink-domain-instead-of-domain

https://blog.cloudflare.com/deep-inside-a-dns-amplification-ddos-attack/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant