TL;DR : RustDNS is a recursive DNS resolver written in plain Rust with zero dependencies , just std::net::UdpSocket and a 512-byte array. It parses DNS packets by hand, follows compression pointers, starts every lookup at a root server and walks the tree down to the answer, then serves that answer…
An SPF record may cost at most 10 DNS lookups while a receiver checks it. One more and the result is permerror . The record is then broken for every message, including mail from servers it does list (RFC 7208, section 4.6.4). Online checkers count for you. Counting once by hand is still worth it…
A healthtech platform cannot treat a successful domain check as permanent evidence. Application logs preserve the product's decisions; live DNS zone reads capture a later observation. Customers keep control of their zones, while the platform still has to explain what it accepted, when it checked…
A domain list is a surprisingly useful dataset. Which of your 500 customer domains expire this quarter? Which lead domains were registered last month (often a trust signal)? Which of your own domains have no DMARC record? All of it is public data, but getting it for a whole list means juggling…
Three recent incidents, one lesson: agents fail at the ordinary infrastructure around the model. An OpenAI agent reached the internet over DNS and ran for about 2.5 hours before a human stopped it. An agent-like attacker chained two zero-days to root at the Dutch Institute for Vulnerability…
TL;DR: For customer-owned storefront domains, I treat every DNS record type as a contract chosen by the system that reads it. SPF and DMARC publish TXT records, a CNAME cannot share its name, and MX is the case where priority carries meaning. My code requires the type at every call site. That turns…
Microsoft's September Patch Tuesday landed a record-setting pile of roughly 970 new CVEs, and two of them are already being exploited. Buried in that pile is the one I would patch first: CVE-2026-69730, a CVSS 9.8 remote code execution in the Windows DNS Server role. No authentication, no user…
On September 3, Mullvad announced it is shutting down the public encrypted DNS servers it has run since 2022 and sponsoring Quad9 instead. If you never typed one of their addresses into anything, you can stop reading. I did, more than once: a DoT endpoint in my laptop's systemd-resolved config and…
TL;DR: Treat a DNS change as a typed publication with three identities: environment, customer, and zone. Resolve all three from the request, compare them with independently loaded expectations, and stop before any write when they disagree. If staging records appeared in a production zone, the…
TL;DR: Keep a marketplace's mail zone under customer control when its team already operates DNS. Before retrying verification, read the expected MX set from durable state, query DNS, normalize both sets, and classify the difference. A matching set is verified. A nonmatching set is a configuration…