DNS Error Reporting
RFC 9567, “DNS Error Reporting”, is a Proposed Standard document published in April 2024 by R. Arends, M. Larson. The canonical text is published by the RFC Editor.
Abstract
DNS error reporting is a lightweight reporting mechanism that provides the operator of an authoritative server with reports on DNS resource records that fail to resolve or validate. A domain owner or DNS hosting organization can use these reports to improve domain hosting. The reports are based on extended DNS errors as described in RFC 8914.
When a domain name fails to resolve or validate due to a misconfiguration or an attack, the operator of the authoritative server may be unaware of this. To mitigate this lack of feedback, this document describes a method for a validating resolver to automatically signal an error to a monitoring agent specified by the authoritative server. The error is encoded in the QNAME; thus, the very act of sending the query is to report the error.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9567 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9566 Deterministic Networking Packet Replication, Elimination, and Ordering Functions via MPLS over UDP/IP
- RFC 9568 Virtual Router Redundancy Protocol Version 3 for IPv4 and IPv6
- RFC 9565 An Update to the tcpControlBits IP Flow Information Export Information Element
- RFC 9569 The Application-Layer Traffic Optimization Transport Information Publication Service
- RFC 9564 Faster Than Light Speed Protocol
- RFC 9570 Deprecating the Use of Router Alert in LSP Ping
- RFC 9563 SM2 Digital Signature Algorithm for DNSSEC
- RFC 9571 Extension of RFC 6374-Based Performance Measurement Using Synonymous Flow Labels