Release of the caching DNS server PowerDNS Recursor 4.7.0

The release of the caching DNS server PowerDNS Recursor 4.7 is now available, responsible for recursive name resolution. PowerDNS Recursor is built on the same codebase as the PowerDNS Authoritative Server, but the recursive and authoritative DNS servers of PowerDNS develop within different development cycles and are released as separate products. The project's code is distributed under the GPLv2 license.

The server provides tools for remote statistics gathering, supports instant restart, has a built-in engine for connecting handlers in Lua, fully supports DNSSEC, DNS64, RPZ (Response Policy Zones), and allows connecting blacklists. There is an option to record resolution results as BIND zone files. To ensure high performance, modern connection multiplexing mechanisms in FreeBSD, Linux, and Solaris (kqueue, epoll, /dev/poll) are used, as well as a high-performance DNS packet parser capable of handling tens of thousands of parallel requests.

In the new version:

  • The ability to add supplementary records to the responses sent to clients is implemented, allowing for the transfer of useful information without the need to send a separate request (for example, related A and AAAA records can be configured to be attached to responses to MX record requests).
  • The implementation of RFC 9156 requirements for supporting the QNAME minimization mechanism has been realized, enhancing privacy by stopping the full original QNAME from being sent to the upstream server.
  • IPv6 address resolution for DNS servers that are not listed in GR (Glue Record) through which the registrar conveys information about serviced domain DNS servers has been ensured.
  • An experimental implementation of one-way verification for DNS servers' support of the DoT (DNS over TLS) protocol has been proposed.
  • The ability to revert to the parent NS record set if servers the child NS record set does not respond has been added.
  • Support for validating ZONEMD RR records (RFC 8976) retrieved from the cache has been introduced.
  • The capability to attach Lua handlers that are invoked at the resolution completion stage has been added (for example, such handlers can alter the response returned to the client).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster