Technology

DNS Flag Day

By · 27 January 2019

DNS Flag Day

The day the internet could “break”. What happens that day, and why?

A bit of history

The Domain Name System, or DNS, was devised in an era when the internet was young. The protocols of the time breathed trust in one’s fellow human beings, and security took a back seat. Gradually, however, awareness grew that DNS needed to become more robust and needed to include more features in the messages it exchanged.

That’s how, in 1999, EDNS, or Extension mechanisms for DNS came about. With the arrival of EDNS, features like DNSSEC, DNS geolocation, and other security measures such as cookies also became possible in classic DNS messages. Every transition, however, is difficult. Some existing firewalls or DNS implementations weren’t updated, or the EDNS standard was installed incorrectly, meaning recursive resolvers had to build workarounds/patches to keep supporting them.

Need for standardization

We’re now 20 years further along, and the weight of all those patches is starting to add up. Patches on patches, year after year — maintaining this patched software keeps getting more complex and leads to (sometimes dangerous) bugs. These workarounds also cause slower response times and stand in the way of innovation. After all, it’s urgently necessary for everyone to follow the standards, otherwise it becomes difficult to withstand the latest threats, such as DNS amplification, DNS flood, and Layer 7 attacks.

Several major IT players, including the developers of the various recursive resolvers, therefore came together and agreed that, starting February 1, 2019, they would no longer support DNS servers that don’t honor the EDNS standard. All new versions of their software will no longer include the earlier compatibility patches, so there’s a risk that domain names may stop being “resolved” from that day on. Which poses a serious risk: no domain name, no website!

And because this deadline caused a very abrupt transition, the term commonly used in computing circles, “Flag Day”, was used for it.

What does DNS Flag Day actually mean for you?

In concrete terms, this means that any DNS server that isn’t compatible with the EDNS standard, or that’s broken due to using a firewall that isn’t EDNS-compatible, will be considered “dead”, causing your domain name to stop working.

How to prepare yourself for DNS Flag Day?

Organizations like ISPs, hosting companies, and others need to test their current domain, as well as their DNS servers. Tools are available for this, which can be found on the DNS Flag Day website. As a regular user, you can also already check whether your domain name is compliant, via a simple test on that same website.

Are you already a Teamdigital client?

Enjoy that day doing other things, because you won’t experience any impact from DNS Flag Day!
Our nameservers support EDNS 100%.