Wrong regional answer to dns query

dns
#1

Hello,

while using CF’s 1.1.1.1 from Italy, I noticed that a ‘dig AAAA www.netflix,com’ would return a CNAME to www.us-west-2.prodaa.netflix.com, which in turn pings at ~180 ms, while it should return a CNAME to www.eu-west-1.prodaa.netflix.com, which pings at ~30 ms (and is the answer I get with Unbound or Google dns).
I tried using normal dns, DoH and DoT both to MRS and MXP centers.
Does anyone have an answer?

0 Likes

#2

The answer is similar via 8.8.8.8 and 9.9.9.9 US

That is the first stage, second stage Netflix will route you to the closest OpenConnect Edge.
https://openconnect.netflix.com/en/

I believe 1.1.1.1 doesn’t pass EDNS Client Subnet, therefore, Netflix authoritative nameserver can’t figure out the user location.

0 Likes