DNS report reports:
Test Name:
Open DNS servers
Status:
Fail
ERROR: One or more of your nameservers reports that it is an open DNS server. This usually means that anyone in the world can query it. This can cause an excessive load on your DNS server. Also, it is strongly discouraged to have a DNS server be both authoritative for your domain and be recursive (even if it is not open), due to the potential for cache poisoning (with no recursion, there is no cache, and it is impossible to poison it). Also, the bad guys could use your DNS server as part of an attack, by forging their IP address. Problem record(s) are:
Server x.x.x.1. reports that it will do recursive lookups.
Server x.x.x.2. reports that it will do recursive lookups.
Server x.x.x.3. reports that it will do recursive lookups.
I believe this used to be listed as a warning since I setup my cpanel server two years ago but I never thought much of it. Now that they have changed the status to fail I assume they are aware of real-world problems caused by it more than just a tiny tiny bit of load.
1.) is setting named to allow recursive lookups the default for cpanel? Or have I done something wrong.
2.) are people following dnsreport.com's advice now and turning recursive lookups off so cpanel dns will only reply for domains specifically hosted by our servers?
2.) how would this be done?
Test Name:
Open DNS servers
Status:
Fail
ERROR: One or more of your nameservers reports that it is an open DNS server. This usually means that anyone in the world can query it. This can cause an excessive load on your DNS server. Also, it is strongly discouraged to have a DNS server be both authoritative for your domain and be recursive (even if it is not open), due to the potential for cache poisoning (with no recursion, there is no cache, and it is impossible to poison it). Also, the bad guys could use your DNS server as part of an attack, by forging their IP address. Problem record(s) are:
Server x.x.x.1. reports that it will do recursive lookups.
Server x.x.x.2. reports that it will do recursive lookups.
Server x.x.x.3. reports that it will do recursive lookups.
I believe this used to be listed as a warning since I setup my cpanel server two years ago but I never thought much of it. Now that they have changed the status to fail I assume they are aware of real-world problems caused by it more than just a tiny tiny bit of load.
1.) is setting named to allow recursive lookups the default for cpanel? Or have I done something wrong.
2.) are people following dnsreport.com's advice now and turning recursive lookups off so cpanel dns will only reply for domains specifically hosted by our servers?
2.) how would this be done?