Serving Stale Data to Improve DNS Resiliency
RFC 8767, “Serving Stale Data to Improve DNS Resiliency”, is a Proposed Standard document published in March 2020 by D. Lawrence, W. Kumari, P. Sood. It updates RFC 1034, RFC 1035, RFC 2181. The canonical text is published by the RFC Editor.
Abstract
This document defines a method (serve-stale) for recursive resolvers to use stale DNS data to avoid outages when authoritative nameservers cannot be reached to refresh expired data. One of the motivations for serve-stale is to make the DNS more resilient to DoS attacks and thereby make them less attractive as an attack vector. This document updates the definitions of TTL from RFCs 1034 and 1035 so that data can be kept in the cache beyond the TTL expiry; it also updates RFC 2181 by interpreting values with the high-order bit set as being positive, rather than 0, and suggests a cap of 7 days.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8767 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 8766 Discovery Proxy for Multicast DNS-Based Service Discovery
- RFC 8768 Constrained Application Protocol Hop-Limit Option
- RFC 8765 DNS Push Notifications
- RFC 8769 Cryptographic Message Syntax Content Types for Concise Binary Object Representation
- RFC 8764 Apple's DNS Long-Lived Queries Protocol
- RFC 8770 Host Router Support for OSPFv2
- RFC 8763 Deployment Considerations for Information-Centric Networking
- RFC 8771 The Internationalized Deliberately Unreadable Network NOtation