DNS Transport over TCP - Implementation Requirements (RFC7766) Disclosure Number: IPCOM000245368D
Original Publication Date: 2016-Mar-01
Most DNS [RFC1034] transactions take place over UDP [RFC768]. TCP [RFC793] is always used for full zone transfers (using AXFR) and is often used for messages whose sizes exceed the DNS protocol's original 512-byte limit. The growing deployment of DNS Security (DNSSEC) and IPv6 has increased response sizes and therefore the use of TCP. The need for increased TCP use has also been driven by the protection it provides against address spoofing and therefore exploitation of DNS in reflection/amplification attacks. It is now widely used in Response Rate Limiting [RRL1] [RRL2]. Additionally, recent work on DNS privacy solutions such as [DNS-over-TLS] is another motivation to revisit DNS-over-TCP requirements.

Internet Engineering Task Force (IETF)                      J. Dickinson Request for Comments: 7766                                  S. Dickinson Obsoletes: 5966                                                  Sinodun Updates: 1035, 1123                                            R. Bellis Category: Standards Track                                            ISC ISSN: 2070-1721                                                A. Mankin                                                               D. Wessels                                                            Verisign Labs                                                               March 2016

           DNS Transport over TCP - Implementation Requirements


   This document specifies the requirement for support of TCP as a    transport protocol for DNS implementations and provides guidelines    towards DNS-over-TCP performance on par with that of DNS-over-UDP.    This document obsoletes RFC 5966 and therefore updates RFC 1035 and    RFC 1123.

