[GH-ISSUE #272] Respond to queries with recursion desired with REFUSED #136

Open
opened 2026-03-13 15:54:29 +03:00 by kerem · 0 comments
Owner

Originally created by @ryancdotorg on GitHub (Aug 8, 2021).
Original GitHub issue: https://github.com/acme-dns/acme-dns/issues/272

I'm seeing a substantial volume of queries against my server that appear to be DDoS amplification attempts, despite the fact that acme-dns responds with small NXDOMAIN responses. I think responding REFUSED when the recursion desired bit is set might reduce this, can that be added as an option, preferably on by default?

Originally created by @ryancdotorg on GitHub (Aug 8, 2021). Original GitHub issue: https://github.com/acme-dns/acme-dns/issues/272 I'm seeing a substantial volume of queries against my server that appear to be DDoS amplification attempts, despite the fact that acme-dns responds with small NXDOMAIN responses. I think responding REFUSED when the recursion desired bit is set might reduce this, can that be added as an option, preferably on by default?
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/acme-dns#136
No description provided.