I noticed that 1.1.1.1 sometimes returns an RRSIG when a CNAME is queried.
It seems to only happen when the domain is not cached. It’s easy to spot on this domain as the TTL is only 20. It seems to be redundant and other resolvers also don’t return it.
I also noticed that Cloudflare doesn’t always return the same IP addresses when requesting this same CNAME. 1.1.1.1 does not use ECS, so I supposed the answers would always be the same, as all requests are made from 141.101.64.0/24 here (AMS). But I still seem to regularly get different results. Could this be because some queries were made over IPv6? Or does ECS still play a role here?
(@mvavrusa)
$ dig bankieren.rabobank.nl @1.1 +nsid
; <<>> DiG 9.16.1-Ubuntu <<>> bankieren.rabobank.nl @1.1 +nsid
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 5020
;; flags: qr rd ra; QUERY: 1, ANSWER: 12, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; NSID: 32 30 6d 38 37 38 ("20m878")
;; QUESTION SECTION:
;bankieren.rabobank.nl. IN A
;; ANSWER SECTION:
bankieren.rabobank.nl. 7123 IN CNAME bankieren.rabobank.nl.edgekey.net.
bankieren.rabobank.nl.edgekey.net. 21523 IN CNAME e82494.dscb.akamaiedge.net.
bankieren.rabobank.nl. 7123 IN RRSIG CNAME 13 3 7200 20220403200620 20220331190620 6395 rabobank.nl. ZWY65LyyCCURD6a4j5AQjoYOX6J4QCO54xd2+/hcZGb3JWfB08k8szoK adTAVUz2EfzxRKALB9qJDzaZ3mYnDw==
e82494.dscb.akamaiedge.net. 20 IN A 104.110.191.36
e82494.dscb.akamaiedge.net. 20 IN A 104.110.191.39
e82494.dscb.akamaiedge.net. 20 IN A 104.110.191.48
e82494.dscb.akamaiedge.net. 20 IN A 104.110.191.40
e82494.dscb.akamaiedge.net. 20 IN A 104.110.191.33
e82494.dscb.akamaiedge.net. 20 IN A 104.110.191.34
e82494.dscb.akamaiedge.net. 20 IN A 104.110.191.47
e82494.dscb.akamaiedge.net. 20 IN A 104.110.191.44
e82494.dscb.akamaiedge.net. 20 IN A 104.110.191.38
;; Query time: 24 msec
;; SERVER: 1.0.0.1#53(1.0.0.1)
;; WHEN: Thu Mar 31 22:49:55 CEST 2022
;; MSG SIZE rcvd: 395
$ dig bankieren.rabobank.nl @1.1 +nsid
; <<>> DiG 9.16.1-Ubuntu <<>> bankieren.rabobank.nl @1.1 +nsid
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 7142
;; flags: qr rd ra; QUERY: 1, ANSWER: 11, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; NSID: 32 30 6d 35 36 39 ("20m569")
;; QUESTION SECTION:
;bankieren.rabobank.nl. IN A
;; ANSWER SECTION:
bankieren.rabobank.nl. 7141 IN CNAME bankieren.rabobank.nl.edgekey.net.
bankieren.rabobank.nl.edgekey.net. 21541 IN CNAME e82494.dscb.akamaiedge.net.
e82494.dscb.akamaiedge.net. 9 IN A 104.110.191.20
e82494.dscb.akamaiedge.net. 9 IN A 104.110.191.16
e82494.dscb.akamaiedge.net. 9 IN A 104.110.191.22
e82494.dscb.akamaiedge.net. 9 IN A 104.110.191.15
e82494.dscb.akamaiedge.net. 9 IN A 104.110.191.9
e82494.dscb.akamaiedge.net. 9 IN A 104.110.191.11
e82494.dscb.akamaiedge.net. 9 IN A 104.110.191.18
e82494.dscb.akamaiedge.net. 9 IN A 104.110.191.6
e82494.dscb.akamaiedge.net. 9 IN A 104.110.191.17
;; Query time: 20 msec
;; SERVER: 1.0.0.1#53(1.0.0.1)
;; WHEN: Thu Mar 31 22:49:56 CEST 2022
;; MSG SIZE rcvd: 288
$ dig bankieren.rabobank.nl @1.1 +nsid
; <<>> DiG 9.16.1-Ubuntu <<>> bankieren.rabobank.nl @1.1 +nsid
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 10143
;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; NSID: 32 30 6d 35 30 36 ("20m506")
;; QUESTION SECTION:
;bankieren.rabobank.nl. IN A
;; ANSWER SECTION:
bankieren.rabobank.nl. 7035 IN CNAME bankieren.rabobank.nl.edgekey.net.
bankieren.rabobank.nl.edgekey.net. 21435 IN CNAME e82494.dscb.akamaiedge.net.
bankieren.rabobank.nl. 7035 IN RRSIG CNAME 13 3 7200 20220403200620 20220331190620 6395 rabobank.nl. ZWY65LyyCCURD6a4j5AQjoYOX6J4QCO54xd2+/hcZGb3JWfB08k8szoK adTAVUz2EfzxRKALB9qJDzaZ3mYnDw==
e82494.dscb.akamaiedge.net. 20 IN A 84.53.185.201
e82494.dscb.akamaiedge.net. 20 IN A 84.53.185.179
;; Query time: 24 msec
;; SERVER: 1.0.0.1#53(1.0.0.1)
;; WHEN: Thu Mar 31 22:54:23 CEST 2022
;; MSG SIZE rcvd: 283
$ dig bankieren.rabobank.nl @1.1 +nsid
; <<>> DiG 9.16.1-Ubuntu <<>> bankieren.rabobank.nl @1.1 +nsid
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 22231
;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; NSID: 32 30 6d 35 32 32 ("20m522")
;; QUESTION SECTION:
;bankieren.rabobank.nl. IN A
;; ANSWER SECTION:
bankieren.rabobank.nl. 7161 IN CNAME bankieren.rabobank.nl.edgekey.net.
bankieren.rabobank.nl.edgekey.net. 21561 IN CNAME e82494.dscb.akamaiedge.net.
e82494.dscb.akamaiedge.net. 19 IN A 84.53.185.179
e82494.dscb.akamaiedge.net. 19 IN A 84.53.185.201
;; Query time: 16 msec
;; SERVER: 1.0.0.1#53(1.0.0.1)
;; WHEN: Thu Mar 31 22:55:38 CEST 2022
;; MSG SIZE rcvd: 176