What's new

Root Canary Test Results - All ServFail [Red Crosses]

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

That's for your browser isn't it? Root canary is different. IFAIK.
 
Root Canary it back working again, well it is for me!. No more 'Servfail'
Annotation 2020-07-02 213443.png
 
Yes, same here. But .9 looks like other's results.

EDIT:
What are advantages/disadvantages?
I actually think my Quad9 results aren’t ideal because I seem to think nobody is supposed to be validating MD5 or some of the other ones I’m green on. I think I read it somewhere, but can’t remember where (probably an RfC for DNSSEC).

Or do you mean advantages of .11 with ECS?
 
I actually think my Quad9 results aren’t ideal because I seem to think nobody is supposed to be validating MD5 or some of the other ones I’m green on. I think I read it somewhere, but can’t remember where (probably an RfC for DNSSEC).

Or do you mean advantages of .11 with ECS?
.11 w/ ECS
 
It's worth testing both ways and seeing how it works for you. Everybody's combination of local topology and traffic patterns are different enough that small changes in DNS configuration can yield surprising differences in performance.

The down-side of sending ECS is that it gives both CDN operators and anyone snooping traffic (typically between the recursor and the authoritatives, which much of it isn't encrypted) a better chance of figuring out who you are and logging your browsing history and monetizing it or putting it in a dossier.

The up-side is that if you're going to sites hosted on Akamai specifically, you may be directed to a slightly nearer server. An excellent paper quantifying all this was just published two days ago, in fact. For non-Akamai-hosted sites, ECS isn't going to get you a performance advantage on Quad9 or Cloudflare, but would get you almost-Quad9-like performance out of Google or OpenDNS. At the cost of some privacy.
 

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top