Skip to content

Add DNS ECS and split-horizon leakage gates#2276

Open
malb200710-dev wants to merge 1 commit into
UnitOneAI:mainfrom
malb200710-dev:codex/dns-ecs-split-horizon-2269
Open

Add DNS ECS and split-horizon leakage gates#2276
malb200710-dev wants to merge 1 commit into
UnitOneAI:mainfrom
malb200710-dev:codex/dns-ecs-split-horizon-2269

Conversation

@malb200710-dev

Copy link
Copy Markdown

Summary

  • Distinguishes approved enterprise resolver forwarding from unmanaged public resolver bypass.
  • Adds EDNS Client Subnet minimization/risk-acceptance evidence gates.
  • Adds split-horizon/internal suffix and private reverse-zone leakage checks.
  • Expands the DNS security output tables with resolver forwarding and leakage evidence.

Validation

  • Confirmed �ersion: "1.1.0" is present.
  • Confirmed ECS, split-horizon, approved resolver, RFC 7871, and leakage evidence markers are present.
  • Confirmed Markdown code fences are balanced.

Closes #2269.

Requesting Improver - Moderate bounty consideration if accepted. Payment details can be provided privately after acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] dns-security: add ECS and split-horizon leakage checks

1 participant