social.dk-libre.fr is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Search results for tag #dns

artlog boosted

[?]Stéphane Bortzmeyer » 🌐
@bortzmeyer@mastodon.gougere.fr

RFC 10001: Operational Guidelines for DNS Transport in Mixed IPv4/IPv6 Environments

Vous gérez des serveurs dans un environnement où il y a à la fois IPv4 et IPv6 ? Alors, ce va vous aider. La recommandation est que tout serveur DNS, lorsque le réseau a à la fois IPv4 et IPv6, doit pouvoir servir les requêtes avec les deux versions d'IP.

bortzmeyer.org/10001.html

    [?]Ⓥ Gregory Trolliet Ⓐ🔻 🇵🇸 » 🌐
    @faket@veganism.social

    [Veille 📣] autistici.org - Press Release – August 28, 2026
    inventati.org/campaign/press

    Les USA ont placé Autistici/Inventati sur la liste des personnes bloquées (Specially Designated Nationals and Blocked Persons List) avec comme désignation SDGT (Specially Designated Global Terrorist). C'est une décision nationale, qui ne devrait pas avoir de conséquences internationales, sauf que…

    1. Internet est en fait largement un système étasunien, le TLD (Top Level Domain) .org est géré par le PIR, qui se trouve être une structure étasunienne, donc soumise à la loi étasunienne. Elle a donc bloqué la propagation DNS ce qui rend totalement indisponible le site, alors qu'il est encore parfaitement fonctionnel.

    2. Les USA menacent de sanctions secondaires les entreprises faisant du commerce avec des entités sur la liste des personnes bloquées. Ce qui implique que la banque qui gère A/I est censée rompre son contrat avec l'association pour éviter de se faire placer elle aussi sur une liste similaire.

    Il est temps de nous libérer de l'impérialisme étasunien!

    Lien vers cette entrée dans ma veille : liens.declosure.ch/shaare/X-RA
    Toute ma veille est disponible ici : liens.declosure.ch/

    [?]Stéphane Bortzmeyer » 🌐
    @bortzmeyer@mastodon.gougere.fr

    Pas joli, le nom de domaine des serveurs faisant autorité. mastodon.gougere.fr/@DNSresolv

      AodeRelay boosted

      [?]Christian Peach » 🌐
      @chpietsch@fedifreu.de

      RE: fedifreu.de/@chpietsch/1170593

      Mastodon-Admins, verhindert die nächste Spam- und Propagandawelle!

      Die Welle an höchst dubiosen Registrierungsversuchen mit zufälligen Usernames, seltsamen E-Mail-Adressen und sturzlangweiligen oder aus Bios geklauten Begründungen ebbt nicht ab.

      Zum Glück bekommt unser Moderationsteam die meisten spammigen Anträge gar nicht mehr zu sehen, weil ein von @gunchleoc gespendetes und von mir verschlimmbessertes Shellscript alle abblockt, die bekannte Wegwerf-Mailadressen enthalten. Vielen Dank an derjan, der den ersten Pull-Request dafür eingereicht hat! Damit wurde ein Flüchtigkeitsfehler von mir behoben.

      Jetzt muss sich das Moderationsteam nur noch mit den kreativeren Registrierungsanträgen beschäftigen. Ein typisches Muster ist, dass seltsame Maildomains verwendet werden. Wenn diese im auf Mailserver verweisen, die für unsere legitimen User nicht relevant sein dürften, sperre ich die gleich mit. Aktuell sind das z.B. die von spacemail•com aus den USA.

      Ich checke die Maildomains wie die IP-Adressen gern auf der Kommandozeile mit host und whois. Wer kein Linux zur Hand hat, kann unter Android die App Termux (z.B. aus ) nehmen und mit pkg install dnsutils whois diese Tools darin installieren.

      $ host domioni.pro
      domioni.pro mail is handled by 0 mx2.spacemail.com.
      domioni.pro mail is handled by 0 mx1.spacemail.com.

      Aber ihr könnt auch gleich ins Web-Interface eures Mastodon-Accounts mit Admin-Rechten gehen, um seltsame Maildomains zu sperren. Das geht dort: EinstellungenModerationGesperrte E-Mail-DomainsNeue hinzufügen. Nach Eingabe einer Maildomain und Klick auf Domain auflösen passiert automatisch eine Abfrage der zu dieser Domain im DNS hinterlegten Mailserver. Durch Antippen der Kästchen vor mx1.… und mx2.… (s. Screenshot) sperre ich die Mailserver in diesem Fall gleich mit.

      So ergänze ich die vom obigen Script jede Nacht importierte Sperrliste bei Bedarf manuell und gebe den Spammern immer weniger Chancen. Zur Nachahmung empfohlen!

      AodeRelay boosted

      [?]Christian Peach » 🌐
      @chpietsch@fedifreu.de

      RE: fedifreu.de/@chpietsch/1170506

      Liebe Mastodon-Admins,

      wenn ihr nicht Teil einer rechtsextremen (oder von Putin/Trump gesteuerten) Propadandamaschine werden wollt, dann tut was gegen die -Accounts, die sich evt. massenhaft auf euren Instanzen einnisten.

      Was ihr tun könnte, habe ich mit Teilnehmenden des laufenden zusammengetragen.

      Aktuelles Beispiel für diese FakeNews-Kampagnen: newsie.social/@dieKadda/117058

      AodeRelay boosted

      [?]Christian Peach » 🌐
      @chpietsch@fedifreu.de

      Beim habe ich heute zusammen mit @wuffel einen Erfahrungsaustausch angestiftet, bei dem wir beraten haben, wie wir mit der Flut dubioser Mastodon-Account-Anträge umgehen können. Hier sind Notizen dazu:

      Was tun gegen Mastodon-Account-Registrierungen durch Bots & Klickworker?

      Anlass

      FakeNews-Kampagne und ähnliche: about.iftas.org/library/suspec

      Abwehrstrategie E-Mail-Domain

      Mastodon lässt es zu, Account-Registrierungen von bestimmten E-Mail-Domains automatisch zu verwerfen. Ein Massenimport der unten verlinkten Listen ist mit Hilfe des mitgelieferten Server-Tools tootctl möglich.

      Abwehrstrategie IP-Adresse

      Mit Standard-Tools wie host und whois können Linux-User die IP-Adresse(n) untersuchen, die ein Antragsteller verwendet hat. Ein mächtigeres Tool ist wtfis, wenn man die API-Keys einiger Webdienste hinterlegt: github.com/pirxthepilot/wtfis

      Viele der Bots oder Klickworker nutzen Tor, andere Proxies oder Cloud-IPs. Anders gesagt: IPs von Heimanschlüssen sind ein positives Signal.

      Abwehrstrategie Begründung

      Viele Bots und Klickworker benutzen stinklangweilige Begründungen. Manche sind besonders dreist und verwenden die Bios beliebiger Fediverse-Accounts als Begründung. Beim Prüfen dieser Anträge kann es also sinnvoll sein, die Begründung ins Suchfeld einer großen Mastodon-Instanz zu kopieren.

      Sehr sinnvoll erscheint es uns, den Text über dem Antragsformular anzupassen, um Antragsteller aufzufordern, in ihrer Begründung bestimmte Dinge zu erwähnen.

      Eine Lösung für Matrix-Fans

      Für Faule hat die Fediverse Foundation einen Matrix-Bot gebaut, der das Checken der IP-Adresse übernimmt und auch das Freischalten oder Ablehnen via Chat ermöglicht: git.fediverse.foundation/ff_pu

      Allgemeine Anti-DDoS-Maßnahmen

      Gegen Ende sprachen wir über Überlastungsprobleme, die von hemmungslosen »KI«-Crawlern hervorgerufen werden und alle Websites (auch außerhalb des Fediversums) betreffen können. Die bekannten Ansätze sind:

      Ideen für Fallen

      Ein 1-Pixel-PNG mit Link auf ein haltdiefresse.php, welches die nötigen Parameter gleich dem Türsteher übergibt. Beim Skripten könnte das helfen: mastodonpy.readthedocs.io

          Screenshot des Mastodon-Admin-Webinterfaces mit dem ersten Schritt der Funktion „Neue E-Mail-Domain sperren“.

          Alt...Screenshot des Mastodon-Admin-Webinterfaces mit dem ersten Schritt der Funktion „Neue E-Mail-Domain sperren“.

          Screenshot aus dem Admin-Webinterface einer von mir betreuten Mastodon-Instanz. Gezeigt wird der zweite Schritt der Funktion „Neue E-Mail-Domain sperren“. Die beiden MX-Domains habe ich angehakt.

          Alt...Screenshot aus dem Admin-Webinterface einer von mir betreuten Mastodon-Instanz. Gezeigt wird der zweite Schritt der Funktion „Neue E-Mail-Domain sperren“. Die beiden MX-Domains habe ich angehakt.

            [?]nico » 🌐
            @n@gotosocial.tourmentine.com

            Rikiti boosted

            [?]Stéphane Bortzmeyer » 🌐
            @bortzmeyer@mastodon.gougere.fr

            Autistici / Inventati et la censure sur leur nom de domaine

            bortzmeyer.org/autistici.html

            @benjamin

              AodeRelay boosted

              [?]Stefano Marinelli » 🌐
              @stefano@mastodon.bsd.cafe

              Recent events and a thought that had already been lingering in my mind for some time prompted me to register two new domains:

              bsdcafe.eu
              bsdcafe.it

              The first is under European control, the second Italian.

              Although as of today I have no reason for doubts or misgivings, having domains managed by European entities gives me a bit more peace of mind. How to put them to use will be a matter of reflection over the coming months.

              Stay tuned!

                [?]Stéphane Bortzmeyer » 🌐
                @bortzmeyer@mastodon.gougere.fr

                RFC 10037: RDAP Extension for DNS TTL Values

                Puisque le RFC 9803 étend le protocole d'avitaillement EPP pour ajouter des TTL spécifiques aux noms de domaine enregistrés, il était logique que le protocole d'interrogation permette d'obtenir cette information. C'est ce que permet l'extension normalisée dans ce nouveau .

                bortzmeyer.org/10037.html

                  Ash_Crow boosted

                  [?]Neil Brown [he/him/his] » 🌐
                  @neil@mastodon.neilzone.co.uk

                  New blogpost:

                  # Time to drop .legal?

                  Just my ponderings at this point.

                  Perhaps I am over-worrying?

                  neilzone.co.uk/2026/08/time-to

                    [?]ChaCha20Poly1305 » 🌐
                    @camille@mastodon.libre-entreprise.com

                    For re-enabling domain name autistici.org, you can add to Unbound configuration the following lines (that may be changed in the future) :

                    domain-insecure: austistici.org
                    stub-zone:
                    name: "autistici.org"
                    stub-addr: 93.190.126.19
                    stub-addr: 198.167.222.108
                    stub-addr: 185.218.207.228
                    stub-addr: 2a12:4180:dc1:929::42
                    stub-addr: 2a12:4180:dc1:929::42
                    stub-addr: 2a11:7980:1::2:0

                    domain-insecure disable (no more valid DS in the .org zone).

                      AodeRelay boosted

                      [?]computing competence » 🌐
                      @cc@feinste-netzwerke.de

                      Normalerweise leitet die -Anfragen und Routen für TI-Dienste an die Box weiter.
                      Doch wenn die Kommunikation zwischen beiden Systemen unterbrochen ist, scheitert dieser Mechanismus. Ab einem bestimmten Zeitpunkt/Update wird aber die IP-Adresse der OPNsense Firewall blockiert. Dadurch bricht die Verbindung zwischen OPNsense und der KoCo Box ab, mit der Folge, dass sie ihre zentrale Rolle für die (TI) nicht mehr erfüllen kann. Bis jetzt.

                      https://computing-competence.de/news/20260828_kocokobana

                        [?]nico » 🌐
                        @n@gotosocial.tourmentine.com

                        [?]Stéphane Bortzmeyer » 🌐
                        @bortzmeyer@mastodon.gougere.fr

                        Bref, choisissez bien votre domaine de premier niveau (TLD = Top Level Domain).

                          [?]Guillaume-Jean Herbiet » 🌐
                          @gjherbiet@mamot.fr

                          Et que ce n’est pas une bonne pratique d’avoir un serveur derrière un firewall.
                          Et que mettre chaque serveur dans un sous-réseau (si ce n’est un AS) différent, c’est mieux.

                          Et merci à @bortzmeyer pour `check-soaˋ qui est un outil d’analyse très utile.

                            [?]Guillaume-Jean Herbiet » 🌐
                            @gjherbiet@mamot.fr

                            Je sais qu’ils font dans l’archive, mais quelqu’un peut dire à la que le c’est sur le port 53 en ET en depuis une bonne trentaine d’années :

                            ```
                            % check-soa bnf.fr
                            ariane.bnf.fr.
                            193.50.133.237: OK: 2026081807
                            galatee.bnf.fr.
                            193.50.133.202: OK: 2026081807
                            % check-soa --tcp bnf.fr
                            ariane.bnf.fr.
                            193.50.133.237: ERROR: dial tcp 193.50.133.237:53: i/o timeout
                            galatee.bnf.fr.
                            193.50.133.202: ERROR: dial tcp 193.50.133.202:53: i/o timeout
                            ```

                              [?]John Marion :donor: » 🌐
                              @jmarion@infosec.exchange

                              Abusing TXT records by putting the whole static site HTML in there. :thinking_very_hard:

                                Breizh boosted

                                [?]Stéphane Bortzmeyer » 🌐
                                @bortzmeyer@mastodon.gougere.fr



                                « gTLD : de nouvelles extensions [sic] arrivent : .gram, .coin, .agent ou peut-être .meta ? »

                                next.ink/253163/gtld-de-nouvel

                                (Le fédivers est un des rares endroits où les TLD du précédent cycle sont largement utilisés. C'est le cas de .social, par exemple, propriété d'une entreprise commerciale étatsunienne.)

                                  [?]NLnet Labs » 🌐
                                  @nlnetlabs@social.nlnetlabs.nl

                                  NSD Security Release!

                                  As part of our ongoing work to address security issues identified through LLM-assisted security research, we have released NSD 4.15.1.

                                  Read more about the security fixes and the new release on our community forum.

                                  community.nlnetlabs.nl/t/nsd-4

                                    [?]~/phranck :antifa: » 🌐
                                    @phranck@oldbytes.space

                                    Liebe Folglinge... Ich habe alle meine Domains bei bei . Also, NUR die Domains inkl. , Einstellungen. -#Hosting habe ich ganz woanders und Web-Hosting wieder woanders.

                                    Nun moechte ich - und Mailhosting zusammenlegen, damit alles an einem Ort ist.

                                    Welche Hoster in , oder zu mindest in (!) koennt ihr mir empfehlen? Sie sollten einem weitestgehende Freiheit bei der Konfiguration bieten (also den vollen DNS Record Satz, eigene Nameserver, ein Paket ueber mehrere Domains sollte moeglich sein etc.) und kein all zu altbackenes UI haben.

                                    Was koennt ihr mir da empfehlen?
                                    Bitte nicht nennen, was es gibt, das kann ich mir selbst zusammensuchen. Ich haette gern Empfehlungen aus eigener Erfahrung.

                                      Fred de CLX boosted

                                      [?]Stéphane Bortzmeyer » 🌐
                                      @bortzmeyer@mastodon.gougere.fr


                                      C'est assez rare, des MX qui pointent vers deux fournisseurs différents : mastodon.gougere.fr/@DNSresolv

                                        [?]Lorenzo Ancora 🇪🇺🇮🇹 :verified: » 🌐
                                        @LorenzoAncora@ieji.de

                                        DNS4EU is a privacy-first DNS resolver by the European Union and Whalebone, available for free to all European citizens under the GDPR.

                                        The service is anonymized and offers child protection, ad blocking, DNSSEC, IPv4, IPv6, DoH, DoT, and anycast, ensuring excellent privacy and minimal latency regardless of your location.

                                        Your browsing data stays within the EU and is protected from cyber threats without being monetized!

                                        joindns4.eu

                                        DNS4EU public DNS service logo and Co-funded by the European Union logo.
Caption: Launch of Secured Privacu-oriented Public DNS resolver.

                                        Alt...DNS4EU public DNS service logo and Co-funded by the European Union logo. Caption: Launch of Secured Privacu-oriented Public DNS resolver.

                                          [?]ChaCha20Poly1305 » 🌐
                                          @camille@mastodon.libre-entreprise.com

                                          @bortzmeyer Au niveau RFC 6014, le statut actuel n'est pas suffisant ? @shaft

                                            [?]ChaCha20Poly1305 » 🌐
                                            @camille@mastodon.libre-entreprise.com

                                            @shaft @bortzmeyer pour l'instant je reste en ED25519 pour toutes les zones de production que je gère mais justement j'aurais voulu tester les problèmes en ML-DSA-44 (en signant du-mlsdsa44.teste.des.services)

                                              JP Mens boosted

                                              [?]Miek Gieben » 🌐
                                              @miekg@mastodon.nl

                                              Liked those short Curve RRSIG's in DNSSEC?

                                              Well, that time is over, good lord. Post quantum RRSIGs with MLDSA44, codeberg.org/miekg/dns/pulls/9

                                                [?]John Shaft » 🌐
                                                @shaft@piaille.fr

                                                3901 is now obsoleted

                                                “This document provides guidelines and documents best current practice for operating authoritative servers, recursive resolvers, and stub resolvers in a mixed / environment."

                                                RFC 10001: Operational Guidelines for DNS Transport in Mixed IPv4/IPv6 Environments
                                                rfc-editor.org/info/rfc10001/

                                                  [?]Haack’s Networking » 🌐
                                                  @oemb1905@gnulinux.social

                                                  Some services will be momentarily down today while we migrate from Dynadot to Dreamhost for our domain Registrar. Moving forward, all DNS will be managed at Hurricane Electric and/or Dreamhost. Thanks for patience 🙏🏼

                                                  This sudden change was due to Dynadot changing their subdomain record policy from 250 to 50 without notice. This caused a week-long disruption in building out new services due to any record over the cap being irrecoverable once deleted and new ones being impossible to create. Despite having 150+ records in the past, Dynadot responded that they've never supported more than 150 and would only restore that.

                                                  Both the change in terms and contract without notice and the dishonesty once a ticket was filed serve as sufficient reasons to ditch Dynadot. This was surprising to say the least. They've been a solid Registrar. As for DNS, we only used it the last three years having originally used afraid.org for over a decade. Ultimately, this is for the best however, because it is always unwise to keep one's DNS and Registrar at the same host. Hurricane Electric's DNS is additionally a breath of fresh air from 1998-2002 era and so easy to use - the alphabetical rendering of records amazing 🤩

                                                  It's always DNS !!

                                                    [?]Rui Nibau (rnb) » 🌐
                                                    @rnb@framapiaf.org

                                                    @sebsauvage Et hop : installée sur la qui me sert de serveur d'applications web locales.

                                                    Il faut apparemment définir cette machine comme __unique__ serveur dans les configurations de la box (dixit la documentation).

                                                      [?]nico » 🌐
                                                      @n@gotosocial.tourmentine.com

                                                      AodeRelay boosted

                                                      [?]NLnet Labs » 🌐
                                                      @nlnetlabs@social.nlnetlabs.nl

                                                      Today a regular Unbound release, version 1.26.0, with features, maintenance and bug fixes. Enjoy the latest version and thanks to the contributors! And stay cool.

                                                      See for more details and acknowledgment our community post, community.nlnetlabs.nl/t/unbou.

                                                        [?]John Shaft » 🌐
                                                        @shaft@piaille.fr

                                                        One more straw on the camel, but a possibly nice straw if deployed in software

                                                        "This document specifies a method for a DNS client to request additional DNS record types to be delivered alongside the primary record type specified in the Question section of a DNS QUERY (OpCode=0)."

                                                        "For example, it may be desirable to receive the A, AAAA, and HTTPS RRs for a domain name together, rather than having to issue multiple queries."

                                                        10029: DNS Multiple QTYPEs
                                                        rfc-editor.org/info/rfc10029/

                                                          [?]Ryan Castellucci (they/them) :nonbinary_flag: [they/them] » 🌐
                                                          @ryanc@infosec.exchange

                                                          DNS knows where it is because it knows where it isn't: LOC records

                                                            [?]nico » 🌐
                                                            @n@gotosocial.tourmentine.com

                                                            AodeRelay boosted

                                                            [?]Peter N. M. Hansteen » 🌐
                                                            @pitrh@mastodon.social

                                                            In the overnight spam haul at $DAYJOB I found a message from Kevin Liu<kevin@cnnetregistry.com> trying to hawk various .cn domain versions of the name the company rebranded away from some months back.

                                                            Basically the same message as in nxdomain.no/~peter/domain_name (tracked bsdly.blogspot.com/2016/03/dom)

                                                              [?]matthew - retroedge.tech » 🌐
                                                              @matthew@social.retroedge.tech

                                                              Federated protocols of the future should consider designing themselves so that even if they use DNS, it is not the foundation of their own identity system so they are not hopelessly bound to it. Federated networks which have message relaying capability such as Bitcoin or BGP can also span across different networks such as cjdns, Yggdrasil, I2P and of course the outside internet.

                                                              https://thegoodwork.substack.com/p/the-next-internet-war

                                                              #federated #DNS #Internet

                                                                Erwan 🚄 boosted

                                                                [?]Codimp » 🌐
                                                                @codimp@social.lithio.fr

                                                                Petit message pour rappeler que si vous avez des zones DNS mais pas de serveurs secondaires, FediNS est là pour ça :

                                                                https://fedins.eu.org

                                                                J'espère pouvoir à un moment bosser sur le fait de fournir aussi un service pour faire du primaire, mais je ne sais pas si un projet existant sympa pour ça existe ou s'il va falloir coder l'outil nous-même …

                                                                #DNS

                                                                  [?]Stéphane Bortzmeyer » 🌐
                                                                  @bortzmeyer@mastodon.gougere.fr

                                                                  AodeRelay boosted

                                                                  [?]NLnet Labs » 🌐
                                                                  @nlnetlabs@social.nlnetlabs.nl

                                                                  Another Unbound security release is now available, addressing a large set of multi-vendor vulnerabilities. In total, Unbound 1.25.2 fixes 24 CVEs.

                                                                  Many thanks to the security researchers who responsibly reported these issues.

                                                                  Release details: community.nlnetlabs.nl/t/unbou

                                                                    [?]sebsauvage » 🌐
                                                                    @sebsauvage@framapiaf.org


                                                                    😱 Le registry (base de données DNS pour le .ro) pour la Roumanie s'est fait attaquer et *entièrement effacer*. Heureusement, ils avaient une copie offline.
                                                                    Ayez toujours un backup déconnecté !
                                                                    cybernews.com/security/hacker-

                                                                    Remi Gacogne boosted

                                                                    [?]Stéphane Bortzmeyer » 🌐
                                                                    @bortzmeyer@mastodon.gougere.fr


                                                                    L'autorité nationale des jeux a annoncé qu'elle demandait le blocage de . J'ai déjà parlé de censure via résolveur menteur à propos d'autres sources de blocage mais je n'avais pas encore parlé de l'.

                                                                    bortzmeyer.org/polymarket-fran

                                                                      AodeRelay boosted

                                                                      [?]tom s » 🌐
                                                                      @tom_s@friendica.ambag.es

                                                                      SSHFP – Fingerprint-Verifizierung via DNS

                                                                      Wenn Sie sich zum ersten Mal mit verbinden, werden Sie gefragt, ob der stimmt. Diese manuelle ist umständlich und fehleranfällig. bietet eine elegante Lösung: Der wird in hinterlegt und vom Client automatisch .

                                                                      Dieser Artikel erklärt, wie SSHFP mit funktioniert, welche Grenzen es hat und warum es in der Praxis selten genutzt wird.

                                                                      linux.ambag.es/devuan/openssh/…

                                                                        [?]adrienandrem » 🌐
                                                                        @adrienandrem@pouet.chapril.org

                                                                        Dites, le synonyme de « test si connecté au web » = « test de ping 8.8.8.8 » m'a l'air tellement bien gravé chez certains.
                                                                        On a une alternative UE ou non GAFAM à automatiquement répliquer ?

                                                                          JP Mens boosted

                                                                          [?]ximon18 » 🌐
                                                                          @ximon18@fosstodon.org

                                                                          The video of my presentation at DNS OARC 46 about progress on our new Rust based DNSSEC signing software Cascade went online today. It’s always fun to look back and see it from the perspective of the audience! For a higher level introduction to Cascade there’s also a great presentation that @jpmens gave at NLUUG earlier this year. Check them out at youtu.be/rQH3dey6kHI?si=0cqZga and youtu.be/HyAwFhIwxHM?si=QJiUIu. @dnsoarc

                                                                            [?]Stéphane Bortzmeyer » 🌐
                                                                            @bortzmeyer@mastodon.gougere.fr

                                                                            J'étais surpris que les serveurs faisant autorité pour .ru soient en .net mais apparemment, les Russes sont en train de changer cela : mastodns.net/@diffroot/1169204

                                                                              [?]Dam H. [lui/il] » 🌐
                                                                              @Dam_ned@mamot.fr

                                                                              Tiens le joindns4.eu qui bloque orbot.app (le client pour android) 🤔

                                                                                AodeRelay boosted

                                                                                [?]B'ad Samurai :ifin: [he/him] » 🌐
                                                                                @badsamurai@infosec.exchange

                                                                                Well good thing the American federal government doesn’t rely on a single privately-owned third-party digital identity provider operating on .me!

                                                                                Calvin change my mind meme with the ID.me logo and “is a national security risk” “change my mind”

                                                                                Alt...Calvin change my mind meme with the ID.me logo and “is a national security risk” “change my mind”

                                                                                  [?]Stéphane Bortzmeyer » 🌐
                                                                                  @bortzmeyer@mastodon.gougere.fr

                                                                                  Si vous utilisez le service de messagerie instantanée , vous avez sans doute vu aujourd'hui, que des services ne marchent pas, notamment les liens vers des ressources diverses (images, etc). C'est parce que le registre de noms de domaine du Monténégro l'a décidé. Voyons les détails.

                                                                                  bortzmeyer.org/telegram-on-hol

                                                                                    [?]ᴏᴏᴍ-ᴋɪʟʟᴇʀ: 333[unix.exe]™ » 🌐
                                                                                    @jae@mastodon.bsd.cafe

                                                                                    sometimes you have to solve your own problems. had a specific use-case to not open a browser to check stats/issues on which is an upstream to resolver

                                                                                    being more tui/tty oriented, decided to build a tui dashboard. works pretty nicely. also felt it was good to dual-scope the binary so it can run as an optional web front-end that's very lightweight and customized

                                                                                    this is a 20mb binary and all you need to do is feed it an api key and profile id (if not on default)

                                                                                    we live in an age where it's somewhat trivial to solve your own problems. why wait for others to do it? everything.

                                                                                      [?]Teddy / Domingo (🇨🇵/🇬🇧) » 🌐
                                                                                      @TeddyTheBest@framapiaf.org

                                                                                      Un faux outil d'analyse propage un via 222 dépôts . Un module Go imite un outil de scan et dissimule un chargeur relié à 222 dépôts . Le réseau est actif depuis janvier et diffuse des d’accès distant ainsi que des voleurs de données, selon l’éditeur de Socket
                                                                                      clubic.com/actualite-620971-un

                                                                                        [?]NLnet Labs » 🌐
                                                                                        @nlnetlabs@social.nlnetlabs.nl

                                                                                        @bortzmeyer @oli @jpmens For context, we’re now in “signing co.uk on a regular laptop” territory, with more improvements to come.

                                                                                          JP Mens boosted

                                                                                          [?]NLnet Labs » 🌐
                                                                                          @nlnetlabs@social.nlnetlabs.nl

                                                                                          It's still Friday and we're still doing a Cascade release, so here's 0.1.0-beta5 'Got that holiday feeling'. 🏖️

                                                                                          In this release we're giving you more speed improvements by parallelizing sorting and more memory reduction by improving the handling of NSEC(3) in incremental signing. You can also track all of these improvements with newly introduced metrics.

                                                                                          Thanks again to @bortzmeyer, @oli and @jpmens and others for providing valuable feedback!

                                                                                          github.com/NLnetLabs/cascade/r

                                                                                            [?]Censys » 🌐
                                                                                            @censys@infosec.exchange

                                                                                            Whether you're trying to:
                                                                                            ✓ Triage alerts
                                                                                            ✓ Investigate incidents
                                                                                            ✓ Hunt adversaries
                                                                                            ✓ Defend against emerging campaigns

                                                                                            DNS is now another layer of the Censys Internet Map helping teams decide faster and more accurately across every stage of the security operations workflow: censys.com/blog/censys-expands

                                                                                              [?]Stéphane Bortzmeyer » 🌐
                                                                                              @bortzmeyer@mastodon.gougere.fr

                                                                                              « Souveraineté numérique : l’Afnic désignée pour gérer et développer les extensions Internet des territoires ultramarins » entreprises.gouv.fr/espace-pre

                                                                                              « Transparentes et participatives, avec une gouvernance ouverte et inclusive »

                                                                                                Remi Gacogne boosted

                                                                                                [?]NLnet Labs » 🌐
                                                                                                @nlnetlabs@social.nlnetlabs.nl

                                                                                                Today, we're happy to launch the NSD 4.15.0. This release of our authoritative server includes more than 20 fixes for LLM-assisted security reports. It also improves the Prometheus metrics, as a nice bonus.

                                                                                                community.nlnetlabs.nl/t/nsd-4

                                                                                                  [?]gregR ☯ » 🌐
                                                                                                  @gregr@mamot.fr

                                                                                                  @bortzmeyer @shaft QOTD
                                                                                                  > Yes, following DNS stuff on Mastodon is now part of maintaining DNS...
                                                                                                  Petit jeu : qui est l'auteur ?
                                                                                                  La réponse
                                                                                                  mail-archive.com/dns-operation

                                                                                                    [?]Dๅᴉĸo » 🌐
                                                                                                    @djiko_iko@framapiaf.org

                                                                                                    Hello, j'ai un domaine dont les NS sont aux US et au Canada. Est ce qu'en soi c'est un problème ? Est ce qu'il existe des NS publics fiables en Europe ? Si je cherche, je tombe bien sur des listes des trucs (genre publicdnsserver.com/switzerlan ). Mais je n'ai aucune idée du sérieux de ce genre de listes, pas plus que de l'utilisabilité de ces serveurs dans ce contexte.

                                                                                                    :boost_requested: appréciés

                                                                                                      [?]Erik Nygren :verified: » 🌐
                                                                                                      @nygren@hachyderm.io

                                                                                                      My final draft submission for the day -- this one being related!

                                                                                                      "Indicating IPv6-only SVCB Endpoints and IPv4 Deprecation in the DNS"

                                                                                                      datatracker.ietf.org/doc/html/

                                                                                                      (Likely for @ietf_wg_dnsop given it is extending , although it ties into v6ops and happy as well.)

                                                                                                      Abstract: As the DNS is the primary mechanism for translating from hostnames to IP addresses, it is a logical place to signal that endpoints are IPv6-only. It is thus also a logical place to signal that legacy endpoints supporting IPv4 are being deprecated. This specification introduces two SvcParams for SVCB-compatible RR types that signal IPv6-only endpoints ("ipv6only") as well as deprecated endpoints ("deprecated").

                                                                                                        fredix 🐧 boosted

                                                                                                        [?]Teddy / Domingo (🇨🇵/🇬🇧) » 🌐
                                                                                                        @TeddyTheBest@framapiaf.org

                                                                                                        Après les et les , les ayants droit veulent désormais pouvoir bloquer des réseaux entiers. La lutte contre le piratage pourrait bientôt franchir une nouvelle étape en
                                                                                                        clubic.com/actualite-620074-ap

                                                                                                          BrianKrebs boosted

                                                                                                          [?]Erik Nygren :verified: » 🌐
                                                                                                          @nygren@hachyderm.io

                                                                                                          I wrote a -00 draft for @ietf_wg_dnsop on Domain Delegation Validation, intended to provide a path around the "Sitting Ducks" issues that @briankrebs and many others have called out over the years where DNS Lame Delegations can be hijacked due to lack of validation:

                                                                                                          datatracker.ietf.org/doc/html/

                                                                                                          We split it off of datatracker.ietf.org/doc/html/ because we're really hoping to finally get that done and published.

                                                                                                            Pierre-Yves boosted

                                                                                                            [?]Orhun Parmaksız 👾 » 🌐
                                                                                                            @orhun@fosstodon.org

                                                                                                            Found a TUI for handling DNS changes! 🤯

                                                                                                            🌐 **dnsglobe** — A global DNS propagation checker

                                                                                                            💯 Query 34 DNS resolvers worldwide in parallel, compare results & watch propagation live w/ interactive world map

                                                                                                            🦀 Written in Rust & built with @ratatui_rs

                                                                                                            ⭐ GitHub: github.com/514-labs/dnsglobe

                                                                                                              [?]John Shaft » 🌐
                                                                                                              @shaft@piaille.fr

                                                                                                              Albania's .al was secured for a week or so. Wonder what happened. 🤔

                                                                                                              DS added to root zone : mastodns.net/@diffroot/1168128
                                                                                                              DS removed : mastodns.net/@diffroot/1168577

                                                                                                                🗳
                                                                                                                Vincent 🐡 boosted

                                                                                                                [?]Tom :damnified: » 🌐
                                                                                                                @thomas@metalhead.club

                                                                                                                Help me to check metalhead.club's current CDN performance!

                                                                                                                Check out media.metalhead.club and let me know if the displayed location is the nearest for you.

                                                                                                                There's Germany, USA and Singapore available.

                                                                                                                I'm curious if Bunny DNS works more accurately than Scaleway DNS.

                                                                                                                I'm displayed a location that is near to me:25
                                                                                                                I'm displayed a far location :(:0

                                                                                                                  [?]NLnet Labs » 🌐
                                                                                                                  @nlnetlabs@social.nlnetlabs.nl

                                                                                                                  Please note that we have volunteered to have all of our products and libraries analyzed by LLM tooling, so you can expect security releases for pretty much everything, down to libraries like rpki-rs and projects in maintenance mode like ldns.

                                                                                                                    Fred de CLX boosted

                                                                                                                    [?]NLnet Labs » 🌐
                                                                                                                    @nlnetlabs@social.nlnetlabs.nl

                                                                                                                    We have been working incredibly hard on patching all of the LLM-assisted security reports for our authoritative server NSD.

                                                                                                                    Today, we're happy to launch the NSD 4.15.0rc1 pre-release so you can test the 20+ fixes that are included. This release also improves the Prometheus metrics, as a nice bonus.

                                                                                                                    community.nlnetlabs.nl/t/nsd-4

                                                                                                                      AodeRelay boosted

                                                                                                                      [?]NLnet Labs » 🌐
                                                                                                                      @nlnetlabs@social.nlnetlabs.nl

                                                                                                                      @benjojo While we love working in Rust, designing and building a resolver for the modern era is a massive undertaking.

                                                                                                                      Simply rewriting Unbound in Rust is a non-starter. We are taking gradual steps in reinventing our DNS stack by putting ldns in maintenance mode and investing in our domain library, and sunsetting OpenDNSSEC by launching Cascade.

                                                                                                                      Doing an authoritative server in Rust is definitely in the cards. Then, we can imagine putting all puzzle pieces together for a new resolver.

                                                                                                                        théorie :verified: boosted

                                                                                                                        [?]ézéo » 🌐
                                                                                                                        @ezeo@piaille.fr

                                                                                                                        Où vont les e-mails de la presse française ?

                                                                                                                        On a épluché les DNS de 50 médias : Le Monde, Libération, Ouest-France, Mediapart, Charlie Hebdo, Splann!...

                                                                                                                        Résultat : une majorité confie sa messagerie à Google ou Microsoft. Sous juridiction américaine, Cloud Act inclus.

                                                                                                                        Les médias indépendants s'en sortent généralement mieux.

                                                                                                                        Données publiques, méthodologie ouverte.

                                                                                                                        👉 quihebergelesmails.fr/press

                                                                                                                          mmu_man boosted

                                                                                                                          [?]Stéphane Bortzmeyer » 🌐
                                                                                                                          @bortzmeyer@mastodon.gougere.fr

                                                                                                                          Le sachiez-tu ? Le nom de domaine sci-hub.se n'existe plus mais il y a toujours des FAI français qui le censurent sur leur résolveur (et renvoient 127.0.0.1) atlas.ripe.net/measurements/18

                                                                                                                            [?]Stéphane Bortzmeyer » 🌐
                                                                                                                            @bortzmeyer@mastodon.gougere.fr

                                                                                                                            - Désignation officielle de l'Afnic comme registre de .mq, .gp, .gf, .re, .tf, .yt, .pm et .wf

                                                                                                                            legifrance.gouv.fr/jorf/id/JOR

                                                                                                                            legifrance.gouv.fr/jorf/id/JOR

                                                                                                                              [?]rabenou » 🌐
                                                                                                                              @rabenou@mastodon.online

                                                                                                                              - Désignation de l'AFNIC comme office d'enregistrement chargé de la gestion des noms de domaines de premier niveau en :

                                                                                                                              - « .mq, « .gp », « .gf », « .re » et « .tf » : legifrance.gouv.fr/jorf/id/JOR

                                                                                                                              - « .yt », « .pm » et « .wf » : legifrance.gouv.fr/jorf/id/JOR

                                                                                                                                [?]Lěng Shuāng (冷霜) » 🌐
                                                                                                                                @lw@mastodon.bsd.cafe

                                                                                                                                looking for a database of DNS IOCs, e.g. "if a client queries for domain <X>, it's probably compromised by <Y>". does this exist?

                                                                                                                                  [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                  @bortzmeyer@mastodon.gougere.fr

                                                                                                                                  Tiens, le résolveur 1.1.1.1 (Cloudflare) a désormais des non-opaques (on reconnait le code des aéroports, au lieu de l'ancien système opaque).

                                                                                                                                    [?]Sheldon [he/him] » 🌐
                                                                                                                                    @sysop408@sfba.social

                                                                                                                                    Underrated reason to have proper SPF setup for all of your hosted domain names to hard fail improper sending routes... when you forget to turn off the mail sender on your dev server and you run a batch action that sends out tens of thousands of emails to users.

                                                                                                                                    I saw my inbox fill up with thousands of email notifications since a lot of the notifications were sent to me. The only reason I'm not panicking is because I looked at the mail headers and saw that because the emails were sent from my computer instead of my server, they failed both SPF and DKIM verification checks so any damage should be limited.

                                                                                                                                    Ugh. 😓

                                                                                                                                      [?]John Shaft » 🌐
                                                                                                                                      @shaft@piaille.fr

                                                                                                                                      vannes.bzh ne réponds toujours pas.

                                                                                                                                      Le domaine à 2 serveurs faisant autorité déclarés dans la zone parente :

                                                                                                                                      - sdns2.ovh.net : Il refuse de répondre (comprendre : il dit ne pas faire autorité)
                                                                                                                                      - sdns.pointbzh.fr : serveur également chez OVH et qui lui ne réponds pas

                                                                                                                                        mmu_man boosted

                                                                                                                                        [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                        @bortzmeyer@mastodon.gougere.fr

                                                                                                                                        La Bretagne est épargnée par la canicule mais pas par les pannes . vannes.bzh ne répond plus.

                                                                                                                                          [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                          @bortzmeyer@mastodon.gougere.fr

                                                                                                                                          Cours jeudi et vendredi. Comme d'habitude, si vous avez des domaines cassés et/ou rigolos, n'hésitez pas à les indiquer, on les fera analyser par les étudiant·es.

                                                                                                                                            AodeRelay boosted

                                                                                                                                            [?]LinuxNews.de » 🌐
                                                                                                                                            @linuxnews@social.anoxinon.de

                                                                                                                                            [?]Miod Vallat [he/him] » 🌐
                                                                                                                                            @miodvallat@hostux.social

                                                                                                                                            Q: How do secondary DNS servers know how to update their zones? [SENSITIVE CONTENT]

                                                                                                                                            A: they read about them on AXFR News.

                                                                                                                                              [?]gregR ☯ » 🌐
                                                                                                                                              @gregr@mamot.fr

                                                                                                                                              Je dis ça je dis rien... mais le point.final client.rdap.org/?type=domain&o n'est pas encore enregistré
                                                                                                                                              @shaft

                                                                                                                                                John Shaft boosted

                                                                                                                                                [?]NLnet Labs » 🌐
                                                                                                                                                @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                Cascade supports incremental DNSSEC signing.

                                                                                                                                                It doesn't use a jitter-based mechanism for this like OpenDNSSEC has, but rather a “re-signing schedule” approach.

                                                                                                                                                To help you understand what to expect from the output, and how the associated settings will affect Cascade's behavior, we have documented the functionality here: cascade.docs.nlnetlabs.nl/en/l

                                                                                                                                                  Breizh boosted

                                                                                                                                                  [?]Codimp » 🌐
                                                                                                                                                  @codimp@social.lithio.fr

                                                                                                                                                  Tient on dirait que c'est plus dur qu'avant de trouver un TLD qui héberge un site web.

                                                                                                                                                  On dirait que "ai" et "pn" qui le faisaient avant ne le font plus.

                                                                                                                                                  Et je n'ai trouvé que "uz" qui le fasse (mais en https et sans le certificat pour "uz") …

                                                                                                                                                  #DNS

                                                                                                                                                    [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                    @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                    @firefoxwebdevs Or use the yourself, may be through a fediverse gateway: mastodon.gougere.fr/@DNSresolv

                                                                                                                                                      [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                      @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                      Le sachiez-tu ? Un nom de domaine peut parfaitement être enregistré (et donc ne plus être disponible) sans pour autant être publié dans le . Cela peut être un choix du titulaire ou bien une opération par le BE ou le registre mais le résultat est le même : le DNS vous répond NXDOMAIN (No Such Domain) mais le domaine n'est pas libre. Utilisez donc RDAP (ou whois pour les plus de 60 ans comme moi) pour savoir si le domaine est enregistré.

                                                                                                                                                      (Testez, par exemple, avec en.fr.)

                                                                                                                                                        [?]Marcus Adams » 🌐
                                                                                                                                                        @gerowen@mastodon.social

                                                                                                                                                        It still can't do DoH to an upstream DNS server, but it'll at least encrypt DNS queries within the local network now.

                                                                                                                                                        Title: Windows Server gets DNS over HTTPS (DoH) support

                                                                                                                                                        Subtitle: has finally flipped the switch on a long-awaited Server security upgrade, bringing encrypted to enterprise networks.

                                                                                                                                                        Link: neowin.net/news/windows-server

                                                                                                                                                          [?]NLnet Labs » 🌐
                                                                                                                                                          @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                          It’s Friday release day again with Cascade 0.1.0-beta2 'Donde comen dos, comen tres'. Thanks to the amazing feedback from @jpmens and @gryphius and hard work from the team, our DNSSEC signer has a bunch of fixes and improvements.

                                                                                                                                                          github.com/NLnetLabs/cascade/r

                                                                                                                                                            AodeRelay boosted

                                                                                                                                                            [?]NLnet Labs » 🌐
                                                                                                                                                            @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                            Today we released ldns 1.9.1, which contains a security fix for CVE-2026-10846: Insufficient verification that responses belong to a query. Thanks Pablo Ruiz from ‘codecome.ai’ for the report.

                                                                                                                                                            Read more in the release post:
                                                                                                                                                            community.nlnetlabs.nl/t/ldns-

                                                                                                                                                              JP Mens boosted

                                                                                                                                                              [?]Guillaume-Jean Herbiet » 🌐
                                                                                                                                                              @gjherbiet@mamot.fr

                                                                                                                                                              I wanted to do some reverse lookup while editing a config file in :

                                                                                                                                                              ```
                                                                                                                                                              setlocal iskeyword+=.,:
                                                                                                                                                              setlocal keywordprg=dig\ +short\ -x
                                                                                                                                                              ```

                                                                                                                                                              so I can press `K` with the cursor over an or address in the file, and I will get the corresponding PTR record if it exists.

                                                                                                                                                              This ended up in my `~/.vim/ftplugin/cisco.vim`.

                                                                                                                                                                JP Mens boosted

                                                                                                                                                                [?]NLnet Labs » 🌐
                                                                                                                                                                @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                                With Cascade 0.1.0 beta1 “Slàinte mhath” we begin our journey to the first production release of our signing solution.

                                                                                                                                                                We rewritten our signer from the ground up using a state machine based architecture, ensuring that each zone pipeline is in a single consistent state at all times.

                                                                                                                                                                In addition to built-in pre-signing and pre-publication review hooks, there’s now incremental signing, TSIG support, downstream IXFR, zone persistence, metrics and much more.

                                                                                                                                                                blog.nlnetlabs.nl/cascade-beta

                                                                                                                                                                  JP Mens boosted

                                                                                                                                                                  [?]Terence Eden » 🌐
                                                                                                                                                                  @Edent@mastodon.social

                                                                                                                                                                  🆕 blog! “How many consecutive hyphens can you have in a domain name?”

                                                                                                                                                                  A seemingly simple question which sent me down into the murky depths of standards. How many consecutive hyphens can you have in a domain name? It probably isn't sensible to name your online presence a----------hyphen.com - but is there anything technically…

                                                                                                                                                                  👀 Read more: shkspr.mobi/blog/2026/06/how-m

                                                                                                                                                                    [?]NLnet Labs » 🌐
                                                                                                                                                                    @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                                    @jpmens Ah yes, this link is a more accurate reflection of the past few days. 😄

                                                                                                                                                                    github.com/NLnetLabs/cascade/i

                                                                                                                                                                    TSIG is mentioned 6 times!

                                                                                                                                                                      [?]NLnet Labs » 🌐
                                                                                                                                                                      @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                                      With eight issues and one pull request over the weekend, once again we're incredibly thankful for the effort @jpmens is putting into testing Cascade.

                                                                                                                                                                      Luckily, none of the reports seem to be in the “everything is broken”-category! 😅

                                                                                                                                                                      github.com/NLnetLabs/cascade/i

                                                                                                                                                                        John Shaft boosted

                                                                                                                                                                        [?]NLnet Labs » 🌐
                                                                                                                                                                        @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                                        With the Cascade beta release, the project now also has a dedicated page on our website:

                                                                                                                                                                        nlnetlabs.nl/projects/cascade/

                                                                                                                                                                        Next up: a logo!

                                                                                                                                                                          Erwan 🚄 boosted

                                                                                                                                                                          [?]NLnet Labs » 🌐
                                                                                                                                                                          @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                                          After releasing the Cascade beta, NLnet Labs HQ has a @jpmens vs. @bortzmeyer poll going.

                                                                                                                                                                          A poll that asks “How many GitHub issues will JP Mens and Stephane Bortzmeyer create by Monday?”

                                                                                                                                                                          Alt...A poll that asks “How many GitHub issues will JP Mens and Stephane Bortzmeyer create by Monday?”

                                                                                                                                                                            [?]NLnet Labs » 🌐
                                                                                                                                                                            @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                                            Cascade 0.1.0 beta1 “Slàinte mhath” is out, so this is your opportunity to kick the tires and take it for a spin around your testing grounds!

                                                                                                                                                                            As we gear up to the production release of our DNSSEC signer, we're eager to hear your feedback so we can incorporate it while we add improvements that we still have in the pipeline which we consider essential for production use.

                                                                                                                                                                            Read all about it in our blog post!
                                                                                                                                                                            blog.nlnetlabs.nl/cascade-beta

                                                                                                                                                                              [?]Tom23 » 🌐
                                                                                                                                                                              @Tom23@pouet.chapril.org

                                                                                                                                                                              Mon problème de merdique à la maison s’est résolu tout seul. Comme c’était arrivé à peu près en même temps que la mise en service de mon et que les symptômes faisaient clairement penser à un truc lié au , j’ai passé pas mal de temps à faire du diag sur le sujet. Mais sans réussir à reproduire significativement les erreurs.
                                                                                                                                                                              La seule différence avec aujourd’hui, c’est que les font genre x100 voir x1000 moins de requêtes dns qu’avant.

                                                                                                                                                                                [?]gregR ☯ » 🌐
                                                                                                                                                                                @gregr@mamot.fr

                                                                                                                                                                                > Les SOA quand il y en a un ça va, c'est quand il y en a plusieurs qu'il y a des problèmes…
                                                                                                                                                                                atlas.ripe.net/measurements/17

                                                                                                                                                                                blaeu blaeu-resolve --type SOA --ipv4 --requested=100 shiabank.com.

                                                                                                                                                                                [ns-2evo.shiabank.com. hostmaster.shiabank.com. 1780405930 3600 600 86400 60] : 1 occurrences
                                                                                                                                                                                [ERROR: SERVFAIL] : 3 occurrences
                                                                                                                                                                                [ns-r6gh.shiabank.com. hostmaster.shiabank.com. 1780405930 3600 600 86400 60] : 1 occurrences
                                                                                                                                                                                Test #176129238 done at 2026-06-02T13:12:51Z

                                                                                                                                                                                  [?]Jeroen Ruigrok van der Werven » 🌐
                                                                                                                                                                                  @asmodai@mastodon.social

                                                                                                                                                                                  Given my domain renewal is around the corner, used the opportunity to move this last domain from Gandi to Porkbun.

                                                                                                                                                                                  Served me well over the years, but with all the recent changes, putting my (little) money where my mouth is and move to a better registrar.

                                                                                                                                                                                    Alexandre :freebsd: boosted

                                                                                                                                                                                    [?]BastilleBSD :freebsd: » 🌐
                                                                                                                                                                                    @BastilleBSD@fosstodon.org

                                                                                                                                                                                    More IDN homograph detection research today. This screenshot is a bit horrifying considering how nearly identical many of the invalid entries visually match the valid entry (top).

                                                                                                                                                                                    TIME CLIENT DOMAIN TYPE STATUS SOURCE SEC LATENCY
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. MX CACHE 0.1ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. AAAA FORWARD v SEC 43.1ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A CACHE 0.1ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypat.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypat.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypat.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms

                                                                                                                                                                                    Alt...TIME CLIENT DOMAIN TYPE STATUS SOURCE SEC LATENCY 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. MX CACHE 0.1ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. AAAA FORWARD v SEC 43.1ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A CACHE 0.1ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypat.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypat.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypat.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms

                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                      [?]BastilleBSD :freebsd: » 🌐
                                                                                                                                                                                      @BastilleBSD@fosstodon.org

                                                                                                                                                                                      Screenshot from my custom (Rust) DNS filtering-forwarder with new experimental runtime IDN homograph detection against a predefined protected domain list.

                                                                                                                                                                                      Screenshot results reflect these punycodes:
                                                                                                                                                                                      xn--ggle-55da.com google.com BLOCK
                                                                                                                                                                                      xn--pypl-53dc.com paypal.com BLOCK
                                                                                                                                                                                      xn--pple-43d.com apple.com BLOCK
                                                                                                                                                                                      xn--fiq228c5hs.cn chinese ALLOW

                                                                                                                                                                                      TIME CLIENT DOMAIN TYPE STATUS SOURCE SEC LATENCY
2026-06-01 17:30 UTC 10.89.17.11 FZ. cn. A FORWARD - 450.5ms
2026-06-01 17:30 UTC 10.89.17.11 apple.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-01 17:30 UTC 10.89.17.11 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-01 17:30 UTC 10.89.17.11 google.com. A BLOCKED HOMOGRAPH 0.0ms

                                                                                                                                                                                      Alt...TIME CLIENT DOMAIN TYPE STATUS SOURCE SEC LATENCY 2026-06-01 17:30 UTC 10.89.17.11 FZ. cn. A FORWARD - 450.5ms 2026-06-01 17:30 UTC 10.89.17.11 apple.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-01 17:30 UTC 10.89.17.11 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-01 17:30 UTC 10.89.17.11 google.com. A BLOCKED HOMOGRAPH 0.0ms

                                                                                                                                                                                        [?]John Shaft » 🌐
                                                                                                                                                                                        @shaft@piaille.fr

                                                                                                                                                                                        This month, Berkeley Internet Name Domain better known as BIND celebrates its 40th anniversary! It was first released with BSD 4.3 in June 1986 🥳🎂🎉

                                                                                                                                                                                          Lord boosted

                                                                                                                                                                                          [?]Codimp » 🌐
                                                                                                                                                                                          @codimp@social.lithio.fr

                                                                                                                                                                                          Pour une présentation DNS, est-ce que vous avez des exemples récents de "soucis", genre panne car 2 serveurs DNS seulement dans le même AS/même baie/même bandeau électrique comme BNP Paribas en 2017 ?

                                                                                                                                                                                          Ou d'autres exemples amusant sur du DNS

                                                                                                                                                                                          Le retoot aide la pédagogie ^^

                                                                                                                                                                                          #DNS

                                                                                                                                                                                            1 ★ 0 ↺

                                                                                                                                                                                            [?]oldsysops » 🌐
                                                                                                                                                                                            @oldsysops@social.dk-libre.fr

                                                                                                                                                                                            tiens j'ai un nom de domaine (perso) qui s'est fait pirater et qui pointe vers un ns2.emailverification.info/ns1.emailverification.info ...

                                                                                                                                                                                            bizarre (heureusement pas en "prod")

                                                                                                                                                                                            une recherche rapide m'indique que je suis pas le seul...

                                                                                                                                                                                              [?]Cdrik ⏚🌻 » 🌐
                                                                                                                                                                                              @Bristow_69@framapiaf.org

                                                                                                                                                                                              Je ne comprends pas pourquoi le site web de cette initiative de fourniture de DNS européens (qui inclut un filtrage enfant + antipub) n'est toujours pas traduite en plusieurs langues européennes 🤔

                                                                                                                                                                                              joindns4.eu/

                                                                                                                                                                                              Les DNS Grand Public :

                                                                                                                                                                                              - Protective 86.54.11.1
                                                                                                                                                                                              - Protective + Child Protection 86.54.11.12
                                                                                                                                                                                              - Protective + Ad Blocking 86.54.11.13
                                                                                                                                                                                              - Protective + Child Protection + Ad Blocking 86.54.11.11
                                                                                                                                                                                              - Unfiltered 86.54.11.100

                                                                                                                                                                                              Logo de DNS4EU, le 4 est en jaune, les lettres en gris.

                                                                                                                                                                                              Alt...Logo de DNS4EU, le 4 est en jaune, les lettres en gris.

                                                                                                                                                                                                🗳
                                                                                                                                                                                                Alexandre :freebsd: boosted

                                                                                                                                                                                                [?]BastilleBSD :freebsd: » 🌐
                                                                                                                                                                                                @BastilleBSD@fosstodon.org

                                                                                                                                                                                                If you run your own local DNS servers at home, do you: (select all that apply)

                                                                                                                                                                                                Comment with your preferred DNS stack and privacy friendly DNS providers.

                                                                                                                                                                                                Forward to ISP's DNS servers.:0
                                                                                                                                                                                                Forward to a DNS service (1.1.1.1, 9.9.9.9, etc).:6
                                                                                                                                                                                                Recursively resolve from root servers directly.:7
                                                                                                                                                                                                Encrypt my DNS using DoH, DoT, etc.:7
                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                  [?]Larvitz :fedora: » 🌐
                                                                                                                                                                                                  @Larvitz@burningboard.net

                                                                                                                                                                                                  I self-host the DNS for my domains for more than 20 years now.

                                                                                                                                                                                                  2026 now finally was the year, where I decomissioned the last BIND server and replaced it with a PowerDNS, containerized in Podman :podman: and a SQLite backend.

                                                                                                                                                                                                  I already migrated the hidden-primariy to PowerDNS in 2022 (because of the REST API, compatibility with Traefik, easier DNSSEC handling and the higher flexibility) and now my secondaries are also migrated.

                                                                                                                                                                                                  Nontheless, BIND was one of the most stable pieces of technology that I've ever used. But it also felt a bit unwieldy and old-fashined ins some ways.

                                                                                                                                                                                                    JP Mens boosted

                                                                                                                                                                                                    [?]NLnet Labs » 🌐
                                                                                                                                                                                                    @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                                                                    We released Unbound 1.25.1 just seven days ago and now look at the changelog today. ❤️‍🩹🔥

                                                                                                                                                                                                    github.com/NLnetLabs/unbound/b

                                                                                                                                                                                                      [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                      @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                      @danyork Any city (not too small, however). can do anything.

                                                                                                                                                                                                        [?]🫧 Social coding commons » 🌐
                                                                                                                                                                                                        @smallcircles@social.coop

                                                                                                                                                                                                        @h4ckernews

                                                                                                                                                                                                        Yes, gnutella. I remember.

                                                                                                                                                                                                        > For most was a file transfer tool. This categorization misses a basic function of the . At its core, Gnutella is just a peer-to-peer engine for blobs.

                                                                                                                                                                                                        > We could have used it as a poor man's system, or a global metadata lookup table for key/value pairs, or a matchmaking service for your Unreal Tournament league, but that never really happened. Gnutella was good at providing file downloads that matched search queries, and that is what history remembers it for.

                                                                                                                                                                                                          [?]gregR ☯ » 🌐
                                                                                                                                                                                                          @gregr@mamot.fr

                                                                                                                                                                                                          QOTD
                                                                                                                                                                                                          > Technitium DNS Server est un serveur DNS open source complet : autoritaire, récursif, et relais.
                                                                                                                                                                                                          @bortzmeyer revenez vite de vacances !

                                                                                                                                                                                                            🗳
                                                                                                                                                                                                            mc.fly boosted

                                                                                                                                                                                                            [?]mc.fly [he/him] » 🌐
                                                                                                                                                                                                            @mcfly@milliways.social

                                                                                                                                                                                                            So question:
                                                                                                                                                                                                            "how many authoritative name servers don't support encryption?"

                                                                                                                                                                                                            The internet claims that this is >95%.

                                                                                                                                                                                                            My personal feeling is that this is lower but this might be my bubble, that we're the 5%.

                                                                                                                                                                                                            What's your feeling?

                                                                                                                                                                                                            Plz retoot for reach.

                                                                                                                                                                                                            It is our bubble. We're the 5%, noone else cares:10
                                                                                                                                                                                                            I think it is higher now - a bit, maybe 10% or so:5
                                                                                                                                                                                                            It is significantly higher - more 25%:0
                                                                                                                                                                                                            what the hell is DNS query encryption?:16

                                                                                                                                                                                                            Closed

                                                                                                                                                                                                              Remi Gacogne boosted

                                                                                                                                                                                                              [?]NLnet Labs » 🌐
                                                                                                                                                                                                              @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                                                                              🚨 SECURITY RELEASE 🚨
                                                                                                                                                                                                              Today we released Unbound 1.25.1, which consolidates security fixes for issues reported over a period of time.

                                                                                                                                                                                                              There are fixes for CVE-2026-33278, CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960, CVE-2026-44390 and CVE-2026-44608.

                                                                                                                                                                                                              Please read the release notes carefully and plan to upgrade.

                                                                                                                                                                                                              community.nlnetlabs.nl/t/unbou

                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                [?]BastilleBSD :freebsd: » 🌐
                                                                                                                                                                                                                @BastilleBSD@fosstodon.org

                                                                                                                                                                                                                Pro tip: set `UseDNS no` in your sshd_config to disable reverse DNS lookups for every single ssh connection to your host.

                                                                                                                                                                                                                It provides no filtering or validation purpose, afaik, and seems to only generate excess DNS traffic.

                                                                                                                                                                                                                This lesson brought to you by the 66k DNS lookups in the past 24hrs from a single public facing forgejo jail.

                                                                                                                                                                                                                  [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                  @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                  chinamobile.com has four name servers and they all have the same set of IP addresses.

                                                                                                                                                                                                                    [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                    @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                    Nice and clever trick to recover some of the "anonymized" IP addresses in root name server traffic. ("Anonymization" is often a joke.)

                                                                                                                                                                                                                      [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                      @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                      If your employer is an OARC member, you have access to the data collected by the root name servers. (Talk by Kazunori Fujiwara)

                                                                                                                                                                                                                      As always, working with data is complicated. For instance, some operators (A, B, D, F, H, I, J and L) blur the IP addresses, and it is not documented. (And they don't use the same algorithm.)

                                                                                                                                                                                                                        [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                        @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                        "Gonemaster - A Go implementation of Zonemaster" by Patrik Wallström

                                                                                                                                                                                                                        Instead of using AI, let's use Go :-) Among the good things: native concurrency [I approve]

                                                                                                                                                                                                                        codeberg.org/pawal/gonemaster

                                                                                                                                                                                                                        🐪

                                                                                                                                                                                                                          [?]NLnet Labs » 🌐
                                                                                                                                                                                                                          @nlnetlabs@social.nlnetlabs.nl

                                                                                                                                                                                                                          @ximon18 @dnsoarc after his talk on stage, Ximon will be at the demo table in the lunch area, where he can show all the other tricks Cascade has learned since OARC 45 in Stockholm.

                                                                                                                                                                                                                          Also, make sure to bring your zone files so you can for example see how fast parallel signing by @bal4e really is.

                                                                                                                                                                                                                            [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                            @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                            "It's still broken."

                                                                                                                                                                                                                              Fred de CLX boosted

                                                                                                                                                                                                                              [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                              @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                              The NS set and the associated glue MUST be consistent between parent and child domain. If they are not, the result will depend on wether the resolver is parent-centric or child-centric.

                                                                                                                                                                                                                              (talk by Petr Špaček)

                                                                                                                                                                                                                              At a time, it broke the .cd TLD.

                                                                                                                                                                                                                                [?]Haack’s Networking » 🌐
                                                                                                                                                                                                                                @oemb1905@gnulinux.social

                                                                                                                                                                                                                                Webmin is hardened & clustered w/ three total nodes, ns1, ns2, and ns3 etc. I will eventually add clustered nodes on two other locations so records are still served when one cluster's host is down.

                                                                                                                                                                                                                                tech.haacksnetworking.org/2025 feedback welcome.

                                                                                                                                                                                                                                Added larger tmp directory & source-IPd vhost so webmin won't lock. Obv, make sure you use static, dedicated, & fully hardened external IPs for permitted list.

                                                                                                                                                                                                                                haack's networking business logo

                                                                                                                                                                                                                                Alt...haack's networking business logo

                                                                                                                                                                                                                                  [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                  @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                  Funny that traffic analysis at Salesforce show still a lot of requests for obsolete types like A6, SPF, DLV.

                                                                                                                                                                                                                                    [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                    @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                    Now, let's innovate: about DELEG, the future new system for delegation.

                                                                                                                                                                                                                                    "Authoritative Enrollment of DELEG" by Libor Peltan

                                                                                                                                                                                                                                      [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                      @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                      root zone key rollover under way. (Planned for 11 october.)

                                                                                                                                                                                                                                      "Who in the room has root access to his resolver?" (Lot of hands, this is an OARC meeting.)

                                                                                                                                                                                                                                        [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                        @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                        Wonderful list of things that can go wrong (and therefore, will) in operations.

                                                                                                                                                                                                                                        (Including an error done on friday afternoon and fixed, will you guess, on monday.)

                                                                                                                                                                                                                                          Fred de CLX boosted

                                                                                                                                                                                                                                          [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                          @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                          DNessie, official mascot.

                                                                                                                                                                                                                                          A cute Loch Ness monster standing in the front of the room.

                                                                                                                                                                                                                                          Alt...A cute Loch Ness monster standing in the front of the room.

                                                                                                                                                                                                                                            Fred de CLX boosted

                                                                                                                                                                                                                                            [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                            @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                            "Modeling DNS Queries and Caching to Evaluate the Merits of QNAME Minimization" by Casey Deccio

                                                                                                                                                                                                                                            Great explanation of caching dynamics, by the way.

                                                                                                                                                                                                                                              [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                              @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                              Actually measuring the robustness of the Internet is hard. For instance, for resolvers (the current talk by Maynard Koch), good resolvers, actually used by people, are typically not publically reachable. The open resolvers which are easy to study are typically misconfigured and not actually used.

                                                                                                                                                                                                                                                [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                                @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                                [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                                @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                                Did you know that OARC has its own fediverse instance?

                                                                                                                                                                                                                                                Sticker with a mastodon and the domain name mastodns.net

                                                                                                                                                                                                                                                Alt...Sticker with a mastodon and the domain name mastodns.net

                                                                                                                                                                                                                                                  [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                                  @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                                  Good morning, Edinburgh! First day of the OARC workshop.

                                                                                                                                                                                                                                                  indico.dns-oarc.net/event/56/

                                                                                                                                                                                                                                                  An old stone building (the Writer's Museum).

                                                                                                                                                                                                                                                  Alt...An old stone building (the Writer's Museum).

                                                                                                                                                                                                                                                    [?]nico » 🌐
                                                                                                                                                                                                                                                    @n@gotosocial.tourmentine.com

                                                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                                                    [?]BastilleBSD :freebsd: » 🌐
                                                                                                                                                                                                                                                    @BastilleBSD@fosstodon.org

                                                                                                                                                                                                                                                    Averaging 36.6% block rate on my DNS filtering service across all users.

                                                                                                                                                                                                                                                    In the age of enshittification it's not hard to believe that 1/3 of all DNS queries request adware, malware, trackers, and other crap you don't need.

                                                                                                                                                                                                                                                      [?]Elena Rossini on GoToSocial ⁂ » 🌐
                                                                                                                                                                                                                                                      @elena@aseachange.com

                                                                                                                                                                                                                                                      Dear Fedi friends,
                                                                                                                                                                                                                                                      You know how grateful I am for your help and expertise. I have a burning question and I know some of you may have the correct answer.

                                                                                                                                                                                                                                                      Long story short, I had been doing a deep dive into #WSocial. My exposé published on Friday got 830 retweets!

                                                                                                                                                                                                                                                      I am working on a follow-up piece and there's something I don't understand.

                                                                                                                                                                                                                                                      The homepage of W Social is now redirecting - from wsocial.eu to wsocial.news

                                                                                                                                                                                                                                                      If I put wsocial.news in WHOIS databases, I'm finding very little information about when it was registered. And there's some odd stuff, like showing an IP address in Washington DC - but they are very adamant of being hosted in Europe... and they use bunny.net (Slovenia). What gives?

                                                                                                                                                                                                                                                      #AskFedi #DNS #WhoIs

                                                                                                                                                                                                                                                      a screenshot of DomainTools showing the WHOis record for WSocial.news - it says name servers are from bunny.net but the IP location and ASN are from Datacamp in the US

                                                                                                                                                                                                                                                      Alt...a screenshot of DomainTools showing the WHOis record for WSocial.news - it says name servers are from bunny.net but the IP location and ASN are from Datacamp in the US

                                                                                                                                                                                                                                                        [?]John Shaft » 🌐
                                                                                                                                                                                                                                                        @shaft@piaille.fr

                                                                                                                                                                                                                                                        Just realised that is Internet Standard (STD) 13.

                                                                                                                                                                                                                                                        In Western societies it means that DNS brings, obviously, good luck ☝️

                                                                                                                                                                                                                                                        rfc-editor.org/info/std13

                                                                                                                                                                                                                                                          [?]Stéphane Bortzmeyer » 🌐
                                                                                                                                                                                                                                                          @bortzmeyer@mastodon.gougere.fr

                                                                                                                                                                                                                                                          Encore un correcteur trop zélé (c'est legarcon.net, pas legarçon.net)

                                                                                                                                                                                                                                                            [?]John Shaft » 🌐
                                                                                                                                                                                                                                                            @shaft@piaille.fr

                                                                                                                                                                                                                                                            @jpmens As expected, it was not a problem. :)

                                                                                                                                                                                                                                                              [?]nico » 🌐
                                                                                                                                                                                                                                                              @n@gotosocial.tourmentine.com

                                                                                                                                                                                                                                                              [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                              @Steve12L@mamot.fr

                                                                                                                                                                                                                                                              ⋅ DNS et certificats SSL : les deux clés d'Internet que l'Europe n'a jamais eu en main

                                                                                                                                                                                                                                                              clubic.com/dossier-611791-dns-

                                                                                                                                                                                                                                                                [?]John Shaft » 🌐
                                                                                                                                                                                                                                                                @shaft@piaille.fr

                                                                                                                                                                                                                                                                .de incident is a good reminder that resolver operators really should serve stale data ( 8767) when needed.

                                                                                                                                                                                                                                                                It helps.

                                                                                                                                                                                                                                                                  [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                  @rysiek@mstdn.social

                                                                                                                                                                                                                                                                  DENIC wrote in their status message that "all DNSSEC-signed .de domains are currently affected in their reachability"
                                                                                                                                                                                                                                                                  status.denic.de/pages/incident

                                                                                                                                                                                                                                                                  But it wasn't just DNSSEC-signed domains! For example, bahn.de was down even though it is not DNSSEC-signed.

                                                                                                                                                                                                                                                                  It looks like for DNSSEC-signed zones the DS record in de. was incorrectly signed:
                                                                                                                                                                                                                                                                  dnsviz.net/d/nic.de/afpsNg/dns

                                                                                                                                                                                                                                                                  And for zones that were not signed, the NSEC3 records proving there is no DS record were incorrectly signed:
                                                                                                                                                                                                                                                                  dnsviz.net/d/bahn.de/afpnxQ/dn

                                                                                                                                                                                                                                                                    [?]John Shaft » 🌐
                                                                                                                                                                                                                                                                    @shaft@piaille.fr

                                                                                                                                                                                                                                                                    Please remember that is innocent until proven guilty. AFAIK DNS is working as expected in the case of .de outage

                                                                                                                                                                                                                                                                    'DNS is innocent' in caps against a yellow background

                                                                                                                                                                                                                                                                    Alt...'DNS is innocent' in caps against a yellow background

                                                                                                                                                                                                                                                                      [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                      @rysiek@mstdn.social

                                                                                                                                                                                                                                                                      Here's a thought:

                                                                                                                                                                                                                                                                      The fact that people are experiencing issues with DE sites and asking if CloudFlare is down speaks volumes about the stability of DE ccTLD and the broader DNS compared to big cloud providers.

                                                                                                                                                                                                                                                                      :blobcatcoffee:

                                                                                                                                                                                                                                                                        [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                        @rysiek@mstdn.social

                                                                                                                                                                                                                                                                        DENIC's status page:
                                                                                                                                                                                                                                                                        status.denic.de/

                                                                                                                                                                                                                                                                        Screenshot below in case you're not able to load it (as I said, stuff is going to be intermittently failing).

                                                                                                                                                                                                                                                                        DNSSEC disruption affecting .de domainsPartial Service Disruption

Incident Status

Partial Service Disruption

Components

DNS

Services

DNS Nameservice

May 5, 2026 23:28 CEST
May 5, 2026 21:28 UTC
INVESTIGATING

Frankfurt am Main, 5 May 2026 – DENIC eG is currently experiencing a disruption in its DNS service for .de domains. As a result, all DNSSEC-signed .de domains are currently affected in their reachability.
The root cause of the disruption has not yet been fully identified. DENIC’s technical teams are working intensively on analysis and on restoring stable operations as quickly as possible.
Based on current information, users and operators of .de domains may experience impairments in domain resolution. Further updates will be provided as soon as reliable findings on the cause and recovery are available.
DENIC asks all affected parties for their understanding.
For further enquiries, DENIC can be contacted via the usual channels.

                                                                                                                                                                                                                                                                        Alt...DNSSEC disruption affecting .de domainsPartial Service Disruption Incident Status Partial Service Disruption Components DNS Services DNS Nameservice May 5, 2026 23:28 CEST May 5, 2026 21:28 UTC INVESTIGATING Frankfurt am Main, 5 May 2026 – DENIC eG is currently experiencing a disruption in its DNS service for .de domains. As a result, all DNSSEC-signed .de domains are currently affected in their reachability. The root cause of the disruption has not yet been fully identified. DENIC’s technical teams are working intensively on analysis and on restoring stable operations as quickly as possible. Based on current information, users and operators of .de domains may experience impairments in domain resolution. Further updates will be provided as soon as reliable findings on the cause and recovery are available. DENIC asks all affected parties for their understanding. For further enquiries, DENIC can be contacted via the usual channels.

                                                                                                                                                                                                                                                                          [?]John Shaft » 🌐
                                                                                                                                                                                                                                                                          @shaft@piaille.fr

                                                                                                                                                                                                                                                                          Ok, is innocent. Most of the time. Curious to know what caused .de outage

                                                                                                                                                                                                                                                                            [?]John Shaft » 🌐
                                                                                                                                                                                                                                                                            @shaft@piaille.fr

                                                                                                                                                                                                                                                                            Am I the only one having problems with ?

                                                                                                                                                                                                                                                                            Unbound is throwing me a lot of DNSSEC bogus on some .de domains 🤔

                                                                                                                                                                                                                                                                            $ dig welt.de
                                                                                                                                                                                                                                                                            ...
                                                                                                                                                                                                                                                                            ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 21366
                                                                                                                                                                                                                                                                            ...
                                                                                                                                                                                                                                                                            ; EDE: 6 (DNSSEC Bogus): (validation failure <welt.de. A IN>: signature crypto failed from 2a02:568:0:2::53 for DS welt.de. while building chain of trust)

                                                                                                                                                                                                                                                                              [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                              @rysiek@mstdn.social

                                                                                                                                                                                                                                                                              At this moment, please send to folks at DENIC. They are dealing with a really bad and stressful situation and I am sure they are doing their best to resolve it as soon as possible.

                                                                                                                                                                                                                                                                                John Shaft boosted

                                                                                                                                                                                                                                                                                [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                                @rysiek@mstdn.social

                                                                                                                                                                                                                                                                                Edit: issue seems fixed.

                                                                                                                                                                                                                                                                                Looks like DE ccTLD is unresolvable due to DNSSEC issue:
                                                                                                                                                                                                                                                                                dnsviz.net/d/nic.de/afpsNg/dns

                                                                                                                                                                                                                                                                                😬

                                                                                                                                                                                                                                                                                🧵👇

                                                                                                                                                                                                                                                                                  [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                                  @rysiek@mstdn.social

                                                                                                                                                                                                                                                                                  RE: mastodon.social/@jpmens/116522

                                                                                                                                                                                                                                                                                  IANA has a chance to do the funniest thing ever… :blobcatpeek:

                                                                                                                                                                                                                                                                                    [?]nico » 🌐
                                                                                                                                                                                                                                                                                    @n@gotosocial.tourmentine.com

                                                                                                                                                                                                                                                                                    [?]BastilleBSD :freebsd: » 🌐
                                                                                                                                                                                                                                                                                    @BastilleBSD@fosstodon.org

                                                                                                                                                                                                                                                                                    I am looking for a few more US-based early adopters to provide feedback on a protective DNS service offering aligned with NIST SP 800-81 Rev. 3 (March 2026).

                                                                                                                                                                                                                                                                                    csrc.nist.gov/pubs/sp/800/81/r

                                                                                                                                                                                                                                                                                    This service merges Zero Trust and DNS without requiring client-side agents. Supports mobile devices, browsers, server hardware & IoT.

                                                                                                                                                                                                                                                                                    If you're interested in providing feedback on this service as a free beta tester, email me at:

                                                                                                                                                                                                                                                                                    securednsbeta@techliterate.co

                                                                                                                                                                                                                                                                                      🗳

                                                                                                                                                                                                                                                                                      [?]Areskul » 🌐
                                                                                                                                                                                                                                                                                      @jean_dupont@mastodon.social

                                                                                                                                                                                                                                                                                      Can you reach crocuda.com ?
                                                                                                                                                                                                                                                                                      (it is only)

                                                                                                                                                                                                                                                                                      yes:57
                                                                                                                                                                                                                                                                                      no:11

                                                                                                                                                                                                                                                                                        [?]Arnaud Launay » 🌐
                                                                                                                                                                                                                                                                                        @asl@mastodon.launay.org

                                                                                                                                                                                                                                                                                        Ah, je viens donc de découvrir que drill a été "abandonné", que le nouvel outil s'appelle "dnsi" ... Et qu'il n'a pas l'air beaucoup plus développé non plus.
                                                                                                                                                                                                                                                                                        Faut en revenir à dig ?