spf-discuss
[Top] [All Lists]

Re: Re: DNS load research

2005-03-23 15:26:24
On Wed, 2005-03-23 at 16:27 -0500, Radu Hociung wrote:

I forgot one thing:

After a few minutes of thinking how to fix this, admins figure out that 
by setting their servers to not respond to TXT queries makes the problem 
go away in seconds. UDP queries are not long lived, so if all TXT 
records disapeared at the same time, it would take only a few seconds 
for the storm to go away.

In other words, take SPF away, and the internet is back on its feet.

So how do you explain that SPF is not do blame?

Removing the SPF check stopped the virus from spreading?  Seems all
you've done is greased the channel it was using to propagate, since it
takes less time to use the same amount of bandwidth.

I seriously hope that the admins that are doing the above thinking think
a little bit longer than you've suggested they would.

-- 
Andy Bakun <spf(_at_)leave-it-to-grace(_dot_)com>