I'd speculate the most common reason for using DNS recursion is to allow a non-authoritative name server to return results for any query. This non-authoritative name server usually sits on a network that serves clients with low latency and high bandwidth, like a LAN. The network is typically private, but private is not always the same as secure/closed. Some benefits of running your own DNS are:
* The ability to cache DNS lookup results (speed increase)
* Placing the name server closer to clients (speed increase)
* The ability to blacklist certain zones (security)
And many more, most of which relate to control, speed, and security.
The thing is, none of these advantages are related to running an "open" DNS with recursive queries enabled. I think the core problem is twofold:
1) Many amateur sysadmins don't recognize that running a name server with recursive queries enabled is a security issue.
2) Enabling recursion doesn't automatically require any configuration to secure the client-trust relationship.
Unfortunately, I'm not really smart enough to propose any changes that would help the situation, but I think this represents a high-level overview of the most common problem scenario.
EDIT: It's also worth noting that some DNS servers enable recursive queries by default. Anyone running their own DNS for their zone, but who don't have knowledge of the issues related to recursive DNS will likely be running an open DNS recursor as well. These are commonly servers at web hosts, which have much faster internet connections as well. So it's a matter of getting everyone on board for changing defaults.
I don't understand why anyone puts up with them. I suspect because they have the word "Open" in their name.
Note my example with MSDN took place a while ago so it might be replicable today.
Additionally OpenDNS has some behaviors that network admins aren't crazy about. OpenDNS will return an answer for queries with no authoritative match. For example, if you query `dig noexist.example.com @208.67.222.222` (that's an OpenDNS resolver IP), you'll get answer: 1 and an IP address. This is considered a "feature" by OpenDNS, but from a purist's perspective, it is a breakage.
We do not run our own DNS server for client name-resolution, because we don't have any need for the control it provides. I acknowledge that some people do, however.
That makes them work like Smurf ampliefiers (http://en.wikipedia.org/wiki/Smurf_attack) in the past.
There were 14 open resolvers. Prodding a bit around at them , many of them are just linux machines people in my area put on the internet, and have just installed a DNS server on it, likely for caching purposes, but it isn't set up properly.
Ofcourse these are DSL connections, so the upload rate is likely just 512kbit, but all you need is enough of them.
If a DNS server doesn't perform lookups for any outside server it isnt very useful.
If you think about a web host, with X number of servers that host websites, these are considered the Master DNS servers when the physical domains being hosted reside on those servers.
The public listed DNS servers on your domain WHOIS records are actually the Secondary DNS servers, and these perform the DNS lookups when someone accesses the hosted website on your Master server.
If the Secondary server accepts requests from anyone, even domains it isn't explicitly responsible for, then it is performing recursive lookups.
A more secure configuration is for the Secondary servers to only accept lookups for its own Master servers.
http://en.wikipedia.org/wiki/Name_server#Recursive_query
Thanks in advance!
Honestly, your best bet is to firewall off UDP port 53 to all hosts except ones that are using it as a DNS server.