[DNSOP] Re: [v6ops] Re: Re: Re: Re: Re: Moving DNS64 (RFC6147) to Internet Standard

Brian E Carpenter <[email protected]> Wed, 15 Apr 2026 10:18:49 +1200
Newsgroups gmane.ietf.dnsop,gmane.ietf.v6ops
Message-ID <[email protected]>
It seems to me that we need a draft on "DNS64 Considered Harmful".

Regards/Ngā mihi
    Brian Carpenter

On 15-Apr-26 09:20, Mark Andrews wrote:
> Continuing on:
> 
> I was using my iPhone as a hot spot and tests that just work when normally work just started falling.  This is all because people interfere with address lookups. We have decades of complaints about people interfering with address lookups.  There was the whole Site Finder snafu.
> 
> DNS64 “appears” to work because there are still not a lot of zones that are signed and most of them also are IPv6 enabled.  Add to that all the OS vendors that have been slack in deploying DNSSEC on the devices they ship.
> 
> Now BIND doesn’t do DNS64 as described.  It does an approximation of it.
> 
> DNS64 isn’t needed anywhere. 464XLAT doesn’t needed it.  Discovery of the prefix doesn’t need it. You can just publish an ip4only.arpa zone with the correct AAAA records.
> 
> Figuring out how to do DNS64 correctly  automatically is impossible even ignoring DNSSEC.  You just break things.
_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]