[Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

Thomas Mieslinger miesi at india.com
Fri Feb 17 09:49:08 UTC 2017


ovh changed its MX A records and now my employers Mail relays can't send 
email to ovh.

This may sound unrelated to pdns_recursor but please read on:

Many many domains are wrongly delegated with wrong glue records in the 
tld zone. As of 2017-02-17 10:43:00 CET dig produces the following output:

dig @i.gtld-servers.net. bureauxdeventepro.com

; <<>> DiG 9.10.4-P5 <<>> @i.gtld-servers.net. bureauxdeventepro.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 33279
;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 5, ADDITIONAL: 8
;; WARNING: recursion requested but not available

; EDNS: version: 0, flags:; udp: 4096
;bureauxdeventepro.com.		IN	A

bureauxdeventepro.com.	172800	IN	NS	mx4.ovh.net.
bureauxdeventepro.com.	172800	IN	NS	mx1.ovh.net.
bureauxdeventepro.com.	172800	IN	NS	mxb.ovh.net.
bureauxdeventepro.com.	172800	IN	NS	dns103.ovh.net.
bureauxdeventepro.com.	172800	IN	NS	ns103.ovh.net.

mx4.ovh.net.		172800	IN	A
mx1.ovh.net.		172800	IN	A
mxb.ovh.net.		172800	IN	A
dns103.ovh.net.		172800	IN	AAAA	2001:41d0:1:4a93::1
dns103.ovh.net.		172800	IN	A
ns103.ovh.net.		172800	IN	AAAA	2001:41d0:1:1993::1
ns103.ovh.net.		172800	IN	A

;; Query time: 9 msec
;; WHEN: Fri Feb 17 10:43:40 CET 2017
;; MSG SIZE  rcvd: 288

The real IP address for mx1.ovh.net is How can I make 
pdns_recursor to not store records from the additional section in the 

I understand that this must have a performance impact but having the 
choice between 1000s of customer calls a day "I can't send emails to ovh 
and it is your fault" and buying some more recursor boxes, I clearly 
want more recursor boxes and less disappointed customers.

Cheers Thomas

More information about the Pdns-users mailing list