[Dnsmasq-discuss] NXDOMAIN responses and negative TTL/SOA
Indronil Anik
indronilanik at gmail.com
Thu Sep 17 09:19:37 UTC 2026
Hello everyone,
I have a question about locally generated NXDOMAIN responses in dnsmasq.
I came across this older discussion from 2018:
https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2018q1/012042.html
The answer mentioned that providing TTL information for locally generated
NXDOMAIN responses would require dnsmasq to include an SOA record.
It's been 8 years since that email, and I was wondering if anything has
changed since then?
For example, currently with a blocking rule like:
/example.com/#
dnsmasq returns NXDOMAIN, but there is no SOA record or negative TTL in the
response. Because of that, the client doesn't have anything to use for
negative caching, and some stubborn clients or apps keep querying dnsmasq
again and again for the same domain, which fills the log with a lot of
clutter.
Would you please consider adding SOA records with TTL as a feature?
For context, I'm using dnsmasq-full on OpenWrt in my router.
Thanks,
Indronil.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/attachments/20260917/030a717c/attachment.htm>
More information about the Dnsmasq-discuss
mailing list