On Feb 20, 2013, at 10:21 PM, Vernon Schryver <vjs at rhyolite.com> wrote:

> Today I realize I am being stupid.  Trying to recursively resolve
> requests for A RRs with ANY requests does not get the NSEC records
> required when there are no A records.  I now wonder if DNSSEC is a 
> reason to deprecate ANY.  (deprecating ANY to mitigate reflection
> attacks is wishful thinking)

This confuses me.

If there is any NSEC record that matches the ownername of your query then the type bitmap provides proof of the existent and non-existent records. i.e. you only need one appropriate NSEC for the QTYPE proofs.


