$ (for x in `seq 1 500`; do echo -n "$x "; host -v MYSECRETDOMAIN. 8.8.8.8 2>&1 |grep SOA; done) > data
$ awk '($3 == 899) { print }' data | wc -l
34
That suggests there are about 34 machines near London. Neat!I repeated the test with:
$ (for x in `seq 1 500`; do echo -n "$x "; host -v MYSECRETDOMAIN. 8.8.4.4 2>&1 |grep SOA; done) > data2
$ awk '($3 == 899) { print }' data2 | wc -l
3
which suggests the IP addresses share infrastructure (at least near London!)You can try this sort of thing with other providers to try and map out their internal infrastructure. (1.1.1.1/cloudflare has around 22 machines near me; quad9 has 16; opendns also has 16; verisign has 31; etc).
One thing I tried was making an ad that recorded the cookie id in the impression tracker so I could record the connecting IP addresses in our DNS server. I could then target users who have a particular network provider (or use a particular DNS provider) which could be useful if I want a large number of users who (effectively) ignore DNS caches.
Perhaps Route 53 and Google have setup a system to notify each other when a record changes so they can then request a transfer and have near zero propagation delay.
Note that this notify system is not the same as that proposed in the RFC. This notify system is configured by the admin and is meant to keep secondary servers updated with changes in the primary server, not for general notification of changes to anyone who is interested.
Maybe things have changed, which would be nice. Nowadays I'm on DigitalOcean and they don't let you control the TTL on the SOA record, so you have to be even more careful than with Amazon. Very annoying.
https://datatracker.ietf.org/doc/html/draft-wkumari-dnsop-ha...