Context: A local movie app have this warning to me as I have this domain blocked with NextDNS 👌

  • Trailblazing Braille Taser
    link
    fedilink
    English
    18 months ago

    You’re probably right. Rather than responding with NXDOMAIN, they’re probably synthesizing A or AAAA records that point to their own server. IMO, this is super weird behavior in the era of HTTPS. I’m also pretty sure there’s an IETF RFC that says recursive resolvers “MUST NOT” synthesize address records, but I can’t seem to dig it up on my phone (pun intended ;).

    • @PoolloverNathan
      link
      English
      12 months ago

      It’s an option, default off. If you enable it it prompts you to install the CA for the block page.