Re: [ietf-smtp] SMTP Retrying/Sending Strategy on 452 / 4.5.3

2019-02-13 15:11:47
Nobody that is sane blocks TCP from or to recursive servers.  Those that
argue for blocking DNS/TCP usually do so in the context of authoritative 
Even there it is "Gun, Foot, Shoot" territory.  There are lots of ways TCP is
used in DNS today when answering ordinary queries (not zone transfers).

* answers don’t fit -> TC=1.
* referral doesn’t fit -> TC=1.
* anti spoofing setting TC=1.
* client recovery from multiple BADCOOKIE responses.

If you have a DNSSEC signed zone you will almost certainly be getting some
TCP traffic.

Too many times I have seen authoritative servers send back TC=1 only to be
blocked by a firewall.  Friends don’t let friends block DNS queries with


