Google Public DNS: 70 billion requests a day and counting
googleblog.blogspot.com
googleblog.blogspot.com
1) Tons of random indy web crawlers, mail cannons, etc. use Google Public DNS.
2) We actively discourage large machine-based usage of our service.
Even with some aggressive handling of large machine-based users, we still grow at a crazy clip.Our growth: http://i.imgur.com/znfu9.png
For examples, I use it with a PHP script that hits it a few hundred times and have not yet had a problem. Should I be expecting one?
A few hundred, even if a few hundred per minute, is not a problem.
we operated for about 6 months using the default resolvers than come with the AMIs, then Amazon contacted us, telling us they wanted us to stop using their recursive nameservers... apt-get install bind, point at 127.0.0.1, redeploy AMI, done (in under 5 minutes).
it isn't as if a crawler cares about an extra 250ms from non-cached entries, and the bandwidth from DNS is trivial* compared to that of downloading pages.
... so why would anyone ever offer to pay you/anyone else for a recursive DNS service? it's a trivial problem...
(* say 32 bytes for the query, 64 bytes for the response... 1B lookups is ~64gb, or $3.50 with Amazon's very expensive bandwidth costs)
DNS query sizes are wrong. I'd double each. But still, inexpensive from a bandwidth standpoint. I get it.
when you also take into effect that crawlers are either: bound on sleep() if they're friendly, bound on cpu if doing processing and you have a lot of money for bandwidth, or if you don't have much money, bound on bandwidth.
and given that crawlers tend to be massively parallelised, the DNS query could take minutes and you really still wouldn't care...
(go and read up on Amdahl's law)
Do you mean to switch away from Google Public DNS?
> Guess which they did?
How much did it cost them?
It sounds kind of sleazy (redirecting "no record" to an ad seems a little off to me), but the guys running it are apparently not. The prejudice against redirects to ad pages is more a result of ISPs who take your money and still give you ads, unlike OpenDNS which is free.
It doesn't just seem off. It is off: it's a major violation and a large part of why I don't use OpenDNS.
When a name doesn't resolve, I want to see my browser's page for a DNS failure. I don't want to see ads.
As I said, it makes people mad because ISPs effectively force you to use their DNS, and some use it to serve ads.
Nobody complains about Google serving ads on their pages, but if your ISP inserted ads through some kind of MITM, it would make people pretty angry.
That amounted to about 100 requests every day per infected computer just from us, and ZeroAccess isn't the only one doing it (and isn't a rare trojan).
It benchmarks global (like Google Public DNS and OpenDNS) and regional DNS providers to show which DNS servers would be fastest for you.
You should read up on how CDNs work (http://en.wikipedia.org/wiki/Content_delivery_network) but the gist is essentially that your DNS server determines which content node you're routed to. If your DNS server is your ISP's DNS server it's very likely that you're geographically close.
However, public DNS is usually anycasted to more general regions. In this case, you may be then routed to a content node which is close to the DNS node, but farther from you.
Google actually does support the EDNS extension in order to help solve this problem, but I find it unlikely that ping supports the extension.
This is a big problem with public DNS services. My research group will be releasing a project soon which seeks to alleviate the problem and dynamically choose DNS based on what provides you the best performance.
Edit: Actually I think I may be wrong about one point: IIRC the actual DNS clients don't need to support EDNS-client-subnet in order for it to be used. Only the DNS and authoritative DNS/CDN need to support it. Usually that's a problem because most of the major CDNs don't support it yet, but Google actually does support it on both their CDN and public DNS. Therefore you should be routed based on your prefix when talking to google.com, not the anycasted 8.8.8.8 node. Thus, I have no idea what's going wrong.
Not true, the feature is called GeoDNS and gives you different IP addresses for the same domain based on your DNS server. See Locke1689's reply.
I haven't noticed any difference in load times so I guess it didn't do any harm.
> We don't correlate or combine your information from the temporary or permanent logs with any other data that Google might have about your use of other services, such as data from Web Search and data from advertising on the Google content network.
And they say that the logs are only used for debugging, DoS protection and abuse.
The FAQ makes it even more clear:
> Is information about my queries to Google Public DNS shared with other Google properties, such as Search, Gmail, ads networks, etc.?
> No.
> And they say that the logs are only used for debugging, DoS protection and abuse.
Source?
How is that faster than using a local DNS server?
Deleted comment
That seems overly negative: Google DNS is consistently better performing for me than other public DNS services except for Level 3's 4.2.2.1 &c because I'm on their network.
Google's public DNS uses anycast, so the performance should be good in most places, perhaps your experience is the result of your geographical location or ISP's network?
Care to elaborate on the poisoned reddit records?
Level 3 doesn't actually run a public DNS service, they run DNS servers that happen to permit requests from non-customers. You'd be well advised not to use it outside L3's network.
The basic technique takes advantage of the fact that DNS allows you to provide additional information in a response so the response for ev1l.hax0rs.org can return a reply which says "This is handled by ns.reddit.com. Oh, by the way, ns.reddit.com is 1.2.3.4"; any server which doesn't properly validate that last part would add the incorrect ns.reddit.com record to its local cache and potentially use it to handle requests for other clients.
They describe their protections in details at: http://code.google.com/speed/public-dns/docs/security.html