More mysterious DNS root query traffic from a large cloud/DNS operator (2022)
blog.apnic.net
blog.apnic.net
BTW, if you run your own local DNS resolver and want to do this, see RFC8806 (https://datatracker.ietf.org/doc/html/rfc8806). I use the setup operated by localroot.isi.edu (register with them and they send you a TSIG-protected DNS NOTIFY when the root zone changes).
Can you share some more information on this? I've been thinking of doing so with my OpenBSD server, but my DNS knowledge is limited to the client side.
It just works and has low resource utilization.
If you know the steps -- install software, download root hints file, glance at default config (probably no changes needed), set packet filter rules, start daemon, update DHCP config -- you can be up and running in less than 10 minutes.
If it's your first time, but all of those steps are conceptually clear, I'd allot an hour or so.
I'd recommend Unbound[0] or Knot Resolver[1]. Either will give you fast local caching and private DNS history, with zero maintenance requirements. I literally have not touched my (Unbound) config in ten years.
Though, now that I think about it, there have probably been root hints[2] updates that I should download. (30 sec later: Done!)
0: https://www.nlnetlabs.nl/projects/unbound/about/
An additional bit of setup can also integrate the equivalent of pihole using rpz.
Just read it quickly and you're good to go.
unbound
knot-resolver
Technitium
Yadifa
(I find BIND tiresome and would only recommend core-dns if you know why you want it)
unbound would be my go-to.
---
General advice: Keep your resolver(s) for public DNS dedicated and as isolated as reasonable. Don't point your clients directly to it or configure any custom zones on it. Instead have your existing (I assume, otherwise spin up dnsmasq) DNS servers forward and cache all your actual lookups.
unbound-control dump_infra
I hold onto these records longer by increasing the infra cache settings in Unbound and have a cron job that refreshes them hourly.Mildly annoying because I was only paying my DNS host for 1 million queries-per-month and had to increase my plan. I only get aggregate statistics so I am unable investigate blame.