On Sat, Nov 10, 2018 at 11:30:30AM -0800, Glen wrote: > I apologize for not properly quoting threads, I am traveling to > vacation today, and am in haste. Thanks for making the time to resolve this. > I have generated new signatures for all zones, and manually signaled > all of the Afilias servers (who provide backup DNS for the IETF). I > have observed that those servers have pulled zone transfers from us, > and would expect that this will update and resolve DNSSEC issues > within the next 10-15 minutes (it usually takes about that long to get > through all of Afilias' networks.) > > I will check again at my next stop to ensure that we have resolution. It looks much better now, and my resolver is seeing the expected valid answers from all servers, however DNSViz is reporting some packet drops with queries to the primary "ns0.amsl.com": http://dnsviz.net/d/irtf.org/dnssec/ $ host ns0.amsl.com ns0.amsl.com has address 4.31.198.40 ns0.amsl.com has IPv6 address 2001:1900:3001:11::28 When I manually query the primary with "dig", all looks well, but when I run my copy of the "dnsviz" CLI, I also see the same packet drops. Looking at PCAP files with "tshark", it appears that some sort of stringent rate-limiter may be in place, since queries identical to the ones sent by "dig" go unanswered. The main difference seems to be that "dnsviz" send multiple queries in quick succession, and then waits for multiple answers. It then retransmits the outstanding queries eventually with various changes to the EDNS buffer size, EDNS DO flag, ... Perhaps the packet drops are intentional, but if not, they may be something to investigate. For the IPv4 address, for a total of 60 queries sent, only 5 answers came back. Four of the five responses were delayed by more than a full second. See below for a trimmed to bare essentials "tshark" decode of the traffic. -- Viktor. User Datagram Protocol, Src Port: 25264, Dst Port: 53 Domain Name System (query) Transaction ID: 0x3392 Queries irtf.org: type NS, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 48720, Dst Port: 53 Domain Name System (query) Transaction ID: 0x197c Queries irtf.org: type A, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 25264, Dst Port: 53 Domain Name System (query) Transaction ID: 0x3392 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 3] Queries irtf.org: type NS, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 48720, Dst Port: 53 Domain Name System (query) Transaction ID: 0x197c [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 4] Queries irtf.org: type A, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 53, Dst Port: 25264 Domain Name System (response) Transaction ID: 0x3392 Flags: 0x8400 Standard query response, No error Answer RRs: 7 Authority RRs: 0 Additional RRs: 3 Queries irtf.org: type NS, class IN Answers irtf.org: type NS, class IN, ns ns0.amsl.com irtf.org: type NS, class IN, ns ns1.ams1.afilias-nst.info irtf.org: type NS, class IN, ns ns1.hkg1.afilias-nst.info irtf.org: type NS, class IN, ns ns1.sea1.afilias-nst.info irtf.org: type NS, class IN, ns ns1.yyz1.afilias-nst.info irtf.org: type NS, class IN, ns ns1.mia1.afilias-nst.info irtf.org: type RRSIG, class IN Name: irtf.org Type Covered: NS (authoritative Name Server) (2) Algorithm: RSA/SHA1 (5) Labels: 2 Signature Expiration: Nov 10, 2019 14:21:42.000000000 EST Signature Inception: Nov 10, 2018 13:22:25.000000000 EST Key Tag: 46380 Signer's name: irtf.org Additional records ns0.amsl.com: type A, class IN, addr 4.31.198.40 ns0.amsl.com: type AAAA, class IN, addr 2001:1900:3001:11::28 <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs [Request In: 3] [Time: 1.072754000 seconds] User Datagram Protocol, Src Port: 48720, Dst Port: 53 Domain Name System (query) Transaction ID: 0x197c [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 4] Queries irtf.org: type A, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 53, Dst Port: 48720 Domain Name System (response) Transaction ID: 0x197c Flags: 0x8400 Standard query response, No error Answer RRs: 2 Authority RRs: 7 Additional RRs: 3 Queries irtf.org: type A, class IN Name: irtf.org Answers irtf.org: type A, class IN, addr 4.31.198.44 irtf.org: type RRSIG, class IN Name: irtf.org Type Covered: A (Host Address) (1) Algorithm: RSA/SHA1 (5) Labels: 2 Signature Expiration: Nov 10, 2019 14:21:55.000000000 EST Signature Inception: Nov 10, 2018 13:22:25.000000000 EST Key Tag: 46380 Signer's name: irtf.org Authoritative nameservers irtf.org: type NS, class IN, ns ns0.amsl.com irtf.org: type NS, class IN, ns ns1.yyz1.afilias-nst.info irtf.org: type NS, class IN, ns ns1.ams1.afilias-nst.info irtf.org: type NS, class IN, ns ns1.sea1.afilias-nst.info irtf.org: type NS, class IN, ns ns1.hkg1.afilias-nst.info irtf.org: type NS, class IN, ns ns1.mia1.afilias-nst.info irtf.org: type RRSIG, class IN Name: irtf.org Type Covered: NS (authoritative Name Server) (2) Algorithm: RSA/SHA1 (5) Labels: 2 Signature Expiration: Nov 10, 2019 14:21:42.000000000 EST Signature Inception: Nov 10, 2018 13:22:25.000000000 EST Key Tag: 46380 Signer's name: irtf.org Additional records ns0.amsl.com: type A, class IN, addr 4.31.198.40 ns0.amsl.com: type AAAA, class IN, addr 2001:1900:3001:11::28 <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs [Request In: 4] [Time: 2.125640000 seconds] User Datagram Protocol, Src Port: 16337, Dst Port: 53 Domain Name System (query) Transaction ID: 0xe5a9 Queries irtf.org: type MX, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 59476, Dst Port: 53 Domain Name System (query) Transaction ID: 0x389a Queries phfauoewzk.irtf.org: type A, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 8626, Dst Port: 53 Domain Name System (query) Transaction ID: 0xc8e2 Queries irtf.org: type TXT, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 10371, Dst Port: 53 Domain Name System (query) Transaction ID: 0xd05b Queries irtf.org: type CNAME, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 19796, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa093 Queries irtf.org: type SOA, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 42679, Dst Port: 53 Domain Name System (query) Transaction ID: 0x7ee6 Queries irtf.org: type MX, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 64611, Dst Port: 53 Domain Name System (query) Transaction ID: 0xdb59 Queries irtf.org: type AAAA, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 35834, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa44c Queries irtf.org: type DNSKEY, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 63520, Dst Port: 53 Domain Name System (query) Transaction ID: 0x9809 Questions: 1 Queries irtf.org: type DNSKEY, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 16337, Dst Port: 53 Domain Name System (query) Transaction ID: 0xe5a9 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 10] Queries irtf.org: type MX, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 59476, Dst Port: 53 Domain Name System (query) Transaction ID: 0x389a [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 11] Queries phfauoewzk.irtf.org: type A, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 8626, Dst Port: 53 Domain Name System (query) Transaction ID: 0xc8e2 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 12] Queries irtf.org: type TXT, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 10371, Dst Port: 53 Domain Name System (query) Transaction ID: 0xd05b [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 13] Queries irtf.org: type CNAME, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 19796, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa093 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 14] Queries irtf.org: type SOA, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 42679, Dst Port: 53 Domain Name System (query) Transaction ID: 0x7ee6 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 15] Queries irtf.org: type MX, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 64611, Dst Port: 53 Domain Name System (query) Transaction ID: 0xdb59 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 16] Queries irtf.org: type AAAA, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 35834, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa44c [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 17] Queries irtf.org: type DNSKEY, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 63520, Dst Port: 53 Domain Name System (query) Transaction ID: 0x9809 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 18] Queries irtf.org: type DNSKEY, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 53, Dst Port: 59476 Domain Name System (response) Transaction ID: 0x389a Flags: 0x8403 Standard query response, No such name Answer RRs: 0 Authority RRs: 4 Additional RRs: 1 Queries phfauoewzk.irtf.org: type A, class IN Authoritative nameservers irtf.org: type SOA, class IN, mname ns0.amsl.com irtf.org: type RRSIG, class IN Type Covered: SOA (Start Of a zone of Authority) (6) Algorithm: RSA/SHA1 (5) Labels: 2 Signature Expiration: Nov 10, 2019 14:21:25.000000000 EST Signature Inception: Nov 10, 2018 13:22:25.000000000 EST Key Tag: 46380 Signer's name: irtf.org irtf.org: type NSEC, class IN, next domain name www.irtf.org RR type in bit map: A (Host Address) RR type in bit map: NS (authoritative Name Server) RR type in bit map: SOA (Start Of a zone of Authority) RR type in bit map: MX (Mail eXchange) RR type in bit map: TXT (Text strings) RR type in bit map: AAAA (IPv6 Address) RR type in bit map: RRSIG RR type in bit map: NSEC RR type in bit map: DNSKEY RR type in bit map: SPF irtf.org: type RRSIG, class IN Type Covered: NSEC (47) Algorithm: RSA/SHA1 (5) Labels: 2 Signature Expiration: Nov 10, 2019 14:19:52.000000000 EST Signature Inception: Nov 10, 2018 13:22:25.000000000 EST Key Tag: 46380 Signer's name: irtf.org Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs [Request In: 11] [Time: 1.073841000 seconds] User Datagram Protocol, Src Port: 16337, Dst Port: 53 Domain Name System (query) Transaction ID: 0xe5a9 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 10] Queries irtf.org: type MX, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 8626, Dst Port: 53 Domain Name System (query) Transaction ID: 0xc8e2 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 12] Queries irtf.org: type TXT, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 10371, Dst Port: 53 Domain Name System (query) Transaction ID: 0xd05b [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 13] Queries irtf.org: type CNAME, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 19796, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa093 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 14] Queries irtf.org: type SOA, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 42679, Dst Port: 53 Domain Name System (query) Transaction ID: 0x7ee6 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 15] Queries irtf.org: type MX, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 64611, Dst Port: 53 Domain Name System (query) Transaction ID: 0xdb59 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 16] Queries irtf.org: type AAAA, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 35834, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa44c [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 17] Queries irtf.org: type DNSKEY, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 63520, Dst Port: 53 Domain Name System (query) Transaction ID: 0x9809 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 18] Queries irtf.org: type DNSKEY, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 16337, Dst Port: 53 Domain Name System (query) Transaction ID: 0xe5a9 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 10] Queries irtf.org: type MX, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 8626, Dst Port: 53 Domain Name System (query) Transaction ID: 0xc8e2 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 12] Queries irtf.org: type TXT, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 10371, Dst Port: 53 Domain Name System (query) Transaction ID: 0xd05b [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 13] Queries irtf.org: type CNAME, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 19796, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa093 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 14] Queries irtf.org: type SOA, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 42679, Dst Port: 53 Domain Name System (query) Transaction ID: 0x7ee6 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 15] Queries irtf.org: type MX, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 64611, Dst Port: 53 Domain Name System (query) Transaction ID: 0xdb59 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 16] Queries irtf.org: type AAAA, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 35834, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa44c [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 17] Queries irtf.org: type DNSKEY, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 63520, Dst Port: 53 Domain Name System (query) Transaction ID: 0x9809 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 18] Queries irtf.org: type DNSKEY, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 10072, Dst Port: 53 Domain Name System (query) Transaction ID: 0xe5a9 Queries irtf.org: type MX, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 39292, Dst Port: 53 Domain Name System (query) Transaction ID: 0xc8e2 Queries irtf.org: type TXT, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 57345, Dst Port: 53 Domain Name System (query) Transaction ID: 0xd05b Queries irtf.org: type CNAME, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 12474, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa093 Queries irtf.org: type SOA, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 46232, Dst Port: 53 Domain Name System (query) Transaction ID: 0xdb59 Queries irtf.org: type AAAA, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 18594, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa44c Queries irtf.org: type DNSKEY, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 10072, Dst Port: 53 Domain Name System (query) Transaction ID: 0xe5a9 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 45] Queries irtf.org: type MX, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 39292, Dst Port: 53 Domain Name System (query) Transaction ID: 0xc8e2 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 46] Queries irtf.org: type TXT, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 57345, Dst Port: 53 Domain Name System (query) Transaction ID: 0xd05b [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 47] Queries irtf.org: type CNAME, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 12474, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa093 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 48] Queries irtf.org: type SOA, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 46232, Dst Port: 53 Domain Name System (query) Transaction ID: 0xdb59 [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 49] Queries irtf.org: type AAAA, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 18594, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa44c [Expert Info (Warning/Protocol): DNS query retransmission. Original request in frame 50] Queries irtf.org: type DNSKEY, class IN Additional records <Root>: type OPT UDP payload size: 512 1... .... .... .... = DO bit: Accepts DNSSEC security RRs User Datagram Protocol, Src Port: 53, Dst Port: 39292 Domain Name System (response) Transaction ID: 0xc8e2 Flags: 0x8600 Standard query response, No error .... ..1. .... .... = Truncated: Message is truncated Answer RRs: 0 Authority RRs: 0 Additional RRs: 1 Queries irtf.org: type TXT, class IN Additional records <Root>: type OPT UDP payload size: 4096 1... .... .... .... = DO bit: Accepts DNSSEC security RRs [Request In: 46] [Time: 1.098694000 seconds] User Datagram Protocol, Src Port: 35541, Dst Port: 53 Domain Name System (query) Transaction ID: 0xe5a9 Queries irtf.org: type MX, class IN Additional records <Root>: type OPT UDP payload size: 512 0... .... .... .... = DO bit: Cannot handle DNSSEC security RRs User Datagram Protocol, Src Port: 43840, Dst Port: 53 Domain Name System (query) Transaction ID: 0xd05b Queries irtf.org: type CNAME, class IN Additional records <Root>: type OPT UDP payload size: 512 0... .... .... .... = DO bit: Cannot handle DNSSEC security RRs User Datagram Protocol, Src Port: 37575, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa093 Queries irtf.org: type SOA, class IN Additional records <Root>: type OPT UDP payload size: 512 0... .... .... .... = DO bit: Cannot handle DNSSEC security RRs User Datagram Protocol, Src Port: 26621, Dst Port: 53 Domain Name System (query) Transaction ID: 0xdb59 Queries irtf.org: type AAAA, class IN Additional records <Root>: type OPT UDP payload size: 512 0... .... .... .... = DO bit: Cannot handle DNSSEC security RRs User Datagram Protocol, Src Port: 39145, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa44c Queries irtf.org: type DNSKEY, class IN Additional records <Root>: type OPT UDP payload size: 512 0... .... .... .... = DO bit: Cannot handle DNSSEC security RRs User Datagram Protocol, Src Port: 53, Dst Port: 43840 Domain Name System (response) Transaction ID: 0xd05b Flags: 0x8400 Standard query response, No error Answer RRs: 0 Authority RRs: 1 Additional RRs: 1 Queries irtf.org: type CNAME, class IN Authoritative nameservers irtf.org: type SOA, class IN, mname ns0.amsl.com Additional records <Root>: type OPT UDP payload size: 4096 0... .... .... .... = DO bit: Cannot handle DNSSEC security RRs [Request In: 59] [Time: 0.066312000 seconds] User Datagram Protocol, Src Port: 47146, Dst Port: 53 Domain Name System (query) Transaction ID: 0xe5a9 Queries irtf.org: type MX, class IN User Datagram Protocol, Src Port: 60574, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa093 Queries irtf.org: type SOA, class IN User Datagram Protocol, Src Port: 57051, Dst Port: 53 Domain Name System (query) Transaction ID: 0xdb59 Queries irtf.org: type AAAA, class IN User Datagram Protocol, Src Port: 51020, Dst Port: 53 Domain Name System (query) Transaction ID: 0xa44c Queries irtf.org: type DNSKEY, class IN