How I Use Farsight NOD RPZ (Newly Observed Domains) in my DNS FIrewall

Over at my day job we've created a Newly Observed Domains service which tracks domain first sightings and packages them up in various ways that can be used to determine network reputation. As in most advanced DNS-related technologies, my home and guests and family are guinea pigs early adopters scratch monkeys for the new tech. Here, I'll share some recipes.

Response Rate Limiting in the Domain Name System (DNS RRL)

This page describes DNS Response Rate Limiting (DNS RRL) which is an advanced pre-standard feature for domain name servers including CZ-NIC Knot DNS, NLNetLabs NSD, and ISC BIND9.


