10 Jan
2016
10 Jan
'16
1:35 a.m.
On Jan 9, 2016, at 6:56 AM, Bjørn Mork <bjorn@mork.no> wrote:
Randy Bush <randy@psg.com> writes:
today I noticed, that my DNS servers are getting a noticable amount of DNS queries for my IPv4 reverse zone, asking for type A or AAAA.
how strange, as a reverse zone should pretty much be all PTRs
Not always: https://cr.yp.to/djbdns/walldns.html
Maybe someone is testing for walldns presence? Not that it is a particularily good test, but you never know what the kids will do... Nope, that cannot explain AAAA requests so there is probably something else going on.
My guess (with no data) would be a spam run using harvested domain names that didn't weed out silly names (why bother if you're a spammer?). Regards, -drc