Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Redirecting DNS requests can harm the Internet, says ICANN

Privacy and performance issues could arise when DNS operators substitute results for nonexistent domain requests
By Mikael Ricknäs, IDG News Service
November 25, 2009 09:31 AM ET
  • Share/Email
  • Tweet This
  • Comment
  • Print

The Internet Corporation for Assigned Names and Numbers on Tuesday condemned the practice of redirecting Internet users to a third-party Web site or portal when they misspell a Web address and type a domain name that does not exist.

Rather than return an error message for DNS requests for nonexistent domains, some DNS operators send back the IP address of another domain, a process known as NXDOMAIN substitution. The target address is often a Web portal or information site.

Verizon defends redirecting typo traffic

Handling DNS requests this way has a number drawbacks that could lead to the Internet not working properly, according to ICANN.

For example, users sending e-mail to a domain that does not exist should get an immediate error message. However, if the message is redirected to a site set up to handle Web traffic, it's likely to get queued and an error message won't arrive for days, ICANN said.

Also, users will get longer response times if the site to which they're supposed to be redirected goes down.

Redirection sites are prime targets for attacks by hackers that want to send users to their own servers.

There are also privacy issues, according to ICANN. If sensitive data is redirected via a country with a different jurisdiction and local law, there could be consequences for both users and registries, it said.

ICANN, which handles assigning domain names and IP addresses, published its opinions and findings in a draft memo before the introduction of new gTLDs (generic top-level domains).

The organization discourages the practice of redirecting requests for nonexistent domains, and suggested banning it in a draft of the agreement owners of the new gTLDs would have to sign. ICANN wants domain owners wishing to redirect DNS requests to first explain why doing so won't cause any problems.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Partner Content

Simplify Your Branch Infrastructure

Learn how to simplify your branch infrastructure while dramatically increasing app performance with Citrix Branch Repeater.

Download the Free Info Kit

Next-Gen Load Balancing

Free Guide: "Next Gen Load Balancing: 8 Things You Need to Handle Today's Network Traffic" shows you the functionality needed in your next load balancer.

Download the Free Guide

Accelerate Your Web Apps by up to 5x

Free Guide: "The Secret to Getting Maximum Speed from your Web Applications."' Learn how you can deliver Web apps up to 5x faster.

Download the Free Guide

Comments (1)
Login
Forgot your account info?

I have to concur with ICANN on this...By zcjin on November 30, 2009, 2:22 amI have to concur with ICANN on this. DNS redirection does not work for anything but web. Even for web, it probably would be used for phishing, which makes end...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed