[DNSOP] Re: [v6ops] Re: Re: Re: Re: Moving DNS64 (RFC6147) to Internet Standard

"[email protected]" <[email protected]> Wed, 15 Apr 2026 09:14:39 +0200
Newsgroups gmane.ietf.dnsop,gmane.ietf.v6ops
Message-ID <[email protected]>
--===============7024898574781169895==
Content-Type: multipart/alternative;
 boundary="Apple-Mail=_BD574676-41AC-4EED-82A4-B49019E1EB68"


--Apple-Mail=_BD574676-41AC-4EED-82A4-B49019E1EB68
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hi Brian,

I think almost every protocol can be harmful if incorrectly implemented or =
deployed =E2=80=A6 what we may improve in every protocol (and in the case o=
f DNS64) is an applicability statement, how is best implemented/deployed, e=
tc.

What Mark indicates here, if I got it correctly, is in part related to DNS =
deployment in general and in the previous email to RFC1918 addresses. Being=
 fixed already.

Saludos,
Jordi

@jordipalet


> El 15 abr 2026, a las 0:18, Brian E Carpenter <[email protected]=
m> escribi=C3=B3:
>=20
> It seems to me that we need a draft on "DNS64 Considered Harmful".
>=20
> Regards/Ng=C4=81 mihi
>   Brian Carpenter
>=20
> On 15-Apr-26 09:20, Mark Andrews wrote:
>> Continuing on:
>> I was using my iPhone as a hot spot and tests that just work when normal=
ly work just started falling.  This is all because people interfere with ad=
dress lookups. We have decades of complaints about people interfering with =
address lookups.  There was the whole Site Finder snafu.
>> DNS64 =E2=80=9Cappears=E2=80=9D to work because there are still not a lo=
t of zones that are signed and most of them also are IPv6 enabled.  Add to =
that all the OS vendors that have been slack in deploying DNSSEC on the dev=
ices they ship.
>> Now BIND doesn=E2=80=99t do DNS64 as described.  It does an approximatio=
n of it.
>> DNS64 isn=E2=80=99t needed anywhere. 464XLAT doesn=E2=80=99t needed it. =
 Discovery of the prefix doesn=E2=80=99t need it. You can just publish an i=
p4only.arpa zone with the correct AAAA records.
>> Figuring out how to do DNS64 correctly  automatically is impossible even=
 ignoring DNSSEC.  You just break things.



**********************************************
IPv4 is over
Are you ready for the new Internet ?
http://www.theipv6company.com
The IPv6 Company

This electronic message contains information which may be privileged or con=
fidential. The information is intended to be for the exclusive use of the i=
ndividual(s) named above and further non-explicilty authorized disclosure, =
copying, distribution or use of the contents of this information, even if p=
artially, including attached files, is strictly prohibited and will be cons=
idered a criminal offense. If you are not the intended recipient be aware t=
hat any disclosure, copying, distribution or use of the contents of this in=
formation, even if partially, including attached files, is strictly prohibi=
ted, will be considered a criminal offense, so you must reply to the origin=
al sender to inform about this communication and delete it.


--Apple-Mail=_BD574676-41AC-4EED-82A4-B49019E1EB68
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html aria-label=3D"message body"><head><meta http-equiv=3D"content-type" c=
ontent=3D"text/html; charset=3Dutf-8"></head><body style=3D"overflow-wrap: =
break-word; -webkit-nbsp-mode: space; line-break: after-white-space;">Hi Br=
ian,<div><br></div><div>I think almost every protocol can be harmful if inc=
orrectly implemented or deployed =E2=80=A6 what we may improve in every pro=
tocol (and in the case of DNS64) is an applicability statement, how is best=
 implemented/deployed, etc.</div><div><br></div><div>What Mark indicates he=
re, if I got it correctly, is in part related to DNS deployment in general =
and in the previous email to RFC1918 addresses. Being fixed already.</div><=
div><br id=3D"lineBreakAtBeginningOfMessage"><div>
<div>Saludos,<br>Jordi<br><br>@jordipalet<br><br></div>

</div>
<div><br><blockquote type=3D"cite"><div>El 15 abr 2026, a las 0:18, Brian E=
 Carpenter &lt;[email protected]&gt; escribi=C3=B3:</div><br clas=
s=3D"Apple-interchange-newline"><div><div>It seems to me that we need a dra=
ft on "DNS64 Considered Harmful".<br><br>Regards/Ng=C4=81 mihi<br> &nbsp;&n=
bsp;Brian Carpenter<br><br>On 15-Apr-26 09:20, Mark Andrews wrote:<br><bloc=
kquote type=3D"cite">Continuing on:<br>I was using my iPhone as a hot spot =
and tests that just work when normally work just started falling. &nbsp;Thi=
s is all because people interfere with address lookups. We have decades of =
complaints about people interfering with address lookups. &nbsp;There was t=
he whole Site Finder snafu.<br>DNS64 =E2=80=9Cappears=E2=80=9D to work beca=
use there are still not a lot of zones that are signed and most of them als=
o are IPv6 enabled. &nbsp;Add to that all the OS vendors that have been sla=
ck in deploying DNSSEC on the devices they ship.<br>Now BIND doesn=E2=80=99=
t do DNS64 as described. &nbsp;It does an approximation of it.<br>DNS64 isn=
=E2=80=99t needed anywhere. 464XLAT doesn=E2=80=99t needed it. &nbsp;Discov=
ery of the prefix doesn=E2=80=99t need it. You can just publish an ip4only.=
arpa zone with the correct AAAA records.<br>Figuring out how to do DNS64 co=
rrectly &nbsp;automatically is impossible even ignoring DNSSEC. &nbsp;You j=
ust break things.<br></blockquote></div></div></blockquote></div><br></div>=
<br>**********************************************<br>
IPv4 is over<br>
Are you ready for the new Internet ?<br>
http://www.theipv6company.com<br>
The IPv6 Company<br>
<br>
This electronic message contains information which may be privileged or con=
fidential. The information is intended to be for the exclusive use of the i=
ndividual(s) named above and further non-explicilty authorized disclosure, =
copying, distribution or use of the contents of this information, even if p=
artially, including attached files, is strictly prohibited and will be cons=
idered a criminal offense. If you are not the intended recipient be aware t=
hat any disclosure, copying, distribution or use of the contents of this in=
formation, even if partially, including attached files, is strictly prohibi=
ted, will be considered a criminal offense, so you must reply to the origin=
al sender to inform about this communication and delete it.<br>
<br>
</body></html>
--Apple-Mail=_BD574676-41AC-4EED-82A4-B49019E1EB68--


--===============7024898574781169895==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRE5TT1AgbWFp
bGluZyBsaXN0IC0tIGRuc29wQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg
dG8gZG5zb3AtbGVhdmVAaWV0Zi5vcmcK

--===============7024898574781169895==--