Skip to content

DNS, Transitive Trust and How Many is Many

This is a draft agenda: changes are still being made.

Speaker:
Ondřej Surý, ISC
Date:
Time:
Room:
Side Room
Session:
DNS
Duration:
20 min
Transcript:
Not Available
Meetecho chat:
Not Available
Type:
Talk
Slides:
Add to calendar

Abstract

How many DNS queries does it take to resolve a single domain name? The answer might really surprise you and perhaps even alarm you. Depending on a specifici delegation, CNAME chains that CDNs love so much, and cross-domain dependencies, a single cold-cache lookup can trigger hundreds of outgoing queries from a recursive resolver, creating latency for end users and amplifying load on both the resolver and the authoritative DNS servers.

This talk will deep dive into different DNS delegation types - in-domain, in-bailiwick, out-of-bailiwick - and explain how each type of the delegations affects the resolver query chain when the cache is cold. I will show how combining delegations across different TLDs and different domain increase the strain on the DNS ecosystem, and how combining this with CNAME chains leads to explosion of transitive trust dependencies that resolvers must chase before returning a single answer.

Recording

Video will be added soon.

Speaker

Ondřej Surý

Ondřej Surý

Rate this talk

Rating will open: Monday, 18 May 2026 09:00 (+0100).