Florian Weimer wrote:

> Or you cache referrals without storing any name server name.
> Conceptually, this seems to be the much simpler approach.

If you mean the cached referral is tagged with the original query,
the complexity is no different from mine.

If you don't, it's insecure.

Paul Vixie wrote:

> i don't think so, since nameservers can be renumbered without being
> renamed.

TTL, which must be properly configured by zone administrators, takes
care of it.

Masataka Ohta

