I ran a tcpdump during 15 minutes this morning to check how many
servers were not doing UDP checksums on their DNS packets. The result
is: 35% of our DNS traffic is NOT CHECKSUMMED.
Even some important name servers do no checksum their traffic (browse
the list and be surprised).
The list of correct or incorrect name servers are available as:
ftp://ftp.nic.fr/pub/autres/dns-wg/nocksum
ftp://ftp.nic.fr/pub/autres/dns-wg/cksum
---------------
Benoit Grange
NIC France
E-Mail: Benoit.Grange(a)inria.fr