Cloudflare is pretty much the only DNS resolver that doesn't provide the source user's IP address when doing recursive requests.
Archive.is is pretty much the only (big) website that refuses to answer DNS requests at all if they don't include the source IP address.
Cloudflare argues that this improves privacy (nevermind that the user's IP shows up anyway as soon as they try to actually connect). Archive.is argues that this prevents them from doing geographic load balancing (which, as it turns out, just happens to be a separate product that Cloudflare is happy to sell to websites).
archive.is blames Cloudflare, but in reality it's easy to verify that archive.is's nameservers are returning different IP addresses depending on the network you're coming in from. This is clearly broken on their end.
Cloudflare literally can't fix this. archive.is is 100% responsible.
Yes, this is the whole point of (this part of) EDNS. It allows you to direct the traffic to a server close to the end user (geographically or based on peering preferences).
> This is clearly broken on their end.
There are two broken things here:
1. Cloudflare doesn't send the source IP with the DNS request
2. Archive.is would rather not respond to broken requests at all than make a best-effort with a degraded experience
Considering that Cloudflare is pretty much the only public DNS server with this problem, and the only motivation seems to be that it competes with their CDN product, I'm far more sympathetic to Archive.is than to Cloudflare.
> Cloudflare literally can't fix this. archive.is is 100% responsible.
Only Cloudflare can fix this properly. Archive.is can work around it (at the cost of degraded performance), but I can understand why they would want to stand their ground.
Yes, because (as they've stated elsewhere) EDNS subnet information leaks information about a requester's IP.
> Archive.is would rather not respond to broken requests at all than make a best-effort with a degraded experience
Broken responses = the most degraded experience.
Is there any other website that just fails when they aren't handed EDNS subnet information? I've never experienced any.
The requester's IP leaks anyway as soon as they actually try to connect.