
4/13/2016 · Ólafur Guðmundsson
What this post added
This post details Cloudflare's decision and process for deprecating the DNS ANY query type. It explains the rationale behind this decision, citing the lack of legitimate use, abundance of malicious use (particularly in DDoS amplification attacks), and the high computational cost of serving ANY queries, especially with DNSSEC. The post also discusses the community's reaction and the eventual adoption of a 'Refuse ANY' strategy, where a harmless HINFO record is returned instead of a full ANY response, to mitigate amplification attacks while maintaining compatibility.