Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

recommended deletions #1753

Conversation

jeffrey-pinyan-cleandns
Copy link

@jeffrey-pinyan-cleandns jeffrey-pinyan-cleandns commented May 9, 2023

Checklist of required steps

  • Description of Organization

  • Robust Reason for PSL Inclusion

  • DNS verification via dig

  • Run Syntax Checker (make test)

  • Each domain listed in the PRIVATE section has and shall maintain at least two years remaining on registration, and we shall keep the _PSL txt record in place in the respective zone(s) in the affected section

Submitter affirms the following:

  • We are listing any third-party limits that we seek to work around in our rationale such as those between IOS 14.5+ and Facebook (see Issue #1245 as a well-documented example)

  • This request was not submitted with the objective of working around other third-party limits

  • The Guidelines were carefully read and understood, and this request conforms

  • The submission follows the guidelines on formatting and sorting


For Private section requests that are submitting entries for domains that match their organization website's primary domain, please understand that this can have impacts that may not match the desired outcome and take a long time to rollback, if at all.

To ensure that requested changes are entirely intentional, make sure that you read the affectation and propagation expectations, that you understand them, and confirm this understanding.

PR Rollbacks have lower priority, and the volunteers are unable to control when or if browsers or other parties using the PSL will refresh or update.

(Link: about propagation/expectations)

  • Yes, I understand. I could break my organization's website cookies etc. and the rollback timing, etc is acceptable. Proceed.

Description of Organization

I am the VP of Development at CleanDNS, an abuse mitigation platform that aggregates abuse reports for domains and provides registries, registrars, and resellers with an evidenced approach to mitigating abuse of the DNS. We regularly make use of the PSL to identify the registry responsible for a domain nameand for identifying the proper RDAP or WHOIS server for a domain name.

Organization Website: https://www.cleandns.com/

Reason for PSL Inclusion

This pull request follows up on issue 1746, and goes further. These are suggested exclusions rather than inclusions. Each suffix in this list returns either an NXDOMAIN or SERVFAIL in response to a dig.

Number of users this request is being made to serve: presumably the entire PSL community.

DNS Verification via dig

Each suffix in the following blocks of suffixes returns NXDOMAIN or SERVFAIL for its status, and has no SOA or A response:

dig @8.8.8.8 +noall +comment +question +answer *SUFFIX* a *SUFFIX* soa | grep 'status:\|\<A\>\|\<SOA\>'

from #1014 (see also #1741, #1746, #1786)

  • neko.am
  • nyaa.am
  • be.ax
  • cat.ax
  • es.ax
  • eu.ax
  • gg.ax
  • mc.ax
  • us.ax
  • xy.ax
  • nl.ci
  • xx.gl
  • app.gp
  • blog.gt
  • de.gt
  • to.gt
  • be.gy
  • cc.hn
  • blog.kg
  • io.kg
  • jp.kg
  • tv.kg
  • uk.kg
  • us.kg
  • de.ls
  • at.md
  • de.md
  • jp.md
  • to.md
  • indie.porn
  • vxl.sh
  • ch.tc
  • me.tc
  • we.tc
  • nyan.to
  • at.vg
  • blog.vu
  • dev.vu
  • me.vu

from #357

  • tele.amune.org

from #620

  • dh.bytemark.co.uk
  • vm.bytemark.co.uk

from #1089

  • hu.com
  • kr.com
  • uy.com

from bug 712640

  • c.la

from #15

  • r.cdn77.net
  • ssl.origin.cdn77-secure.org

from #815

  • test.ru

from bug 927072

  • cupcake.is

from #107

  • dynv6.net

from #764

  • staging.onred.one

from bug 1155882

  • mc.eu.org

from #713

  • filegear-au.me

from #1181

  • fireweb.app

from #1160

  • flap.id

from #459

  • flynnhosting.net

from #282

  • ro.im

from #294

  • publishproxy.com

of unknown provenance

  • blogspot.mr
  • blogspot.td

from #796

  • hs.zone
  • hs.run

from bug 868331

  • herokussl.com

from #1095

  • lon.wafaicloud.com
  • cloud.jelastic.open.tim.it
  • jelastic.tsukaeru.net
  • jelastic.regruhosting.ru

from #291

  • co.krd

from #1154

  • krellian.net

from #849

  • lelux.site

from #1263

  • cn.vu

from #1081

  • forte.id

from bug 1155496

  • 4u.com

from #560

  • 001www.com
  • hicam.net
  • now-dns.top
  • crafting.xyz

from #531

  • pcloud.host

from bug 849816

  • nyc.mn

from #404

  • cya.gg

from #1039

  • rdv.to

from #1061

  • ent.platform.sh

from #820

  • dyn53.io

from #1568

  • id.firewalledreplit.co

from #300

  • wellbeingzone.eu

from #1507

  • nodes.k8s.fr-par.scw.cloud
  • nodes.k8s.nl-ams.scw.cloud
  • nodes.k8s.pl-waw.scw.cloud

from #302

  • shiftedit.io

from #230

  • alpha.bounty-full.com
  • beta.bounty-full.com

from #1634

  • privatelink.snowflake.app

from #255

  • dev.static.land
  • sites.static.land

from #1363

  • su.paba.se

from #1453

  • beta.tailscale.net

from #880

  • urown.cloud
  • dnsupdate.info

from #331

  • ybo.faith
  • yombo.me
  • ybo.party
  • ybo.review
  • ybo.science
  • ybo.trade

@dnsguru dnsguru added this to To-Do in List Add/Mod/Del via automation Jun 19, 2023
@dnsguru dnsguru added MAY DESERVE SECURITY REVIEW This is a PR that might benefit from a re-review 🩺 pending-validation Something needs to be validated labels Jun 19, 2023
@dnsguru
Copy link
Member

dnsguru commented Jul 5, 2023

This is getting some attention and there are a number of requests that tie to this, #1741 #1746 #1755 #1786

@dnsguru dnsguru linked an issue Jul 5, 2023 that may be closed by this pull request
@jeffrey-pinyan-cleandns
Copy link
Author

This is getting some attention and there are a number of requests that tie to this, #1741 #1746 #1755 #1786

I'll have an update in this afternoon.

@dnsguru
Copy link
Member

dnsguru commented Jul 5, 2023

@jeffrey-pinyan-cleandns Actually, what would be incredibly helpful is to break / separate the ones from the cascading PR for the VOXEL stuff cited in the mentioned numbers

@dnsguru
Copy link
Member

dnsguru commented Jul 5, 2023

AND
if possible, citing the PR that introduced the spaces you're mentioning would be helpful.
#maximumeffort

AND
Additionally, may want to exclude AWS - we get a large number of AMZN/AWS regional requests where they bundle anticipated entries into a larger PR so that they make big requests in lower frequency vs higher volume faster frequency. This leaves some unlit space but saves the anemic volunteer resources at PSL from nickel/dime requests. Same would be true of other hyperscale / cloud infra companies, but see #1605 specific to AWS/Amazon

@dnsguru dnsguru linked an issue Jul 5, 2023 that may be closed by this pull request
@dnsguru
Copy link
Member

dnsguru commented Jul 5, 2023

AND if possible, citing the PR that introduced the spaces you're mentioning would be helpful. #maximumeffort

#1089 for hu.com kr.com uy.com as an example (probably a bad one, as we requested DNS _PSL at that time or left it to gaining registrant)

@jeffrey-pinyan-cleandns jeffrey-pinyan-cleandns marked this pull request as ready for review July 6, 2023 01:11
@jeffrey-pinyan-cleandns
Copy link
Author

The list has been updated and broken into groups by originating pull request or bug report.

@BenjaminEHowe
Copy link
Contributor

I think this list needs to be reviewed carefully. Some of the listed suffixes appear to be in active use, e.g.

While I agree that PSL size modesty is important, IMO entries should only be removed where either (a) the owner of the domain requests it, and / or (b) removing the entry is less bad than retaining it (e.g. see #1638). I think a number of the proposed removals fall short of this threshold.

@jeffrey-pinyan-cleandns, perhaps you could supply reproducible script(s) similar to #1746 demonstrating that the suffixes you propose deleting return NXDOMAIN or SERVFAIL?

@jeffrey-pinyan-cleandns
Copy link
Author

jeffrey-pinyan-cleandns commented Jul 31, 2023

I think this list needs to be reviewed carefully. Some of the listed suffixes appear to be in active use, e.g.

While I agree that PSL size modesty is important, IMO entries should only be removed where either (a) the owner of the domain requests it, and / or (b) removing the entry is less bad than retaining it (e.g. see #1638). I think a number of the proposed removals fall short of this threshold.

@jeffrey-pinyan-cleandns, perhaps you could supply reproducible script(s) similar to #1746 demonstrating that the suffixes you propose deleting return NXDOMAIN or SERVFAIL?

I would not be surprised that the state of some of those suffixes has changed over 3+ weeks.

From the code below, the following suffixes, also listed above, now return NOERROR:

  • nyaa.am
  • be.ax
  • cat.ax
  • gg.ax
  • mc.ax
  • xy.ax
  • nl.ci
  • xx.gl
  • app.gp
  • de.gt
  • to.gt
  • be.gy
  • io.kg
  • uk.kg
  • us.kg
  • de.ls
  • at.md
  • jp.md
  • to.md
  • vxl.sh
  • me.tc
  • nyan.to
  • at.vg
  • fireweb.app
  • 4u.com
#!/usr/bin/perl

use strict;
use warnings;

while (my $zone = <DATA>) {
  chomp $zone;
  warn "$zone\n";
  print qx{dig \@8.8.8.8 +noall +comment +question +answer $zone a $zone soa | grep 'status:\\|\\<A\\>\\|\\<SOA\\>'};
}

__DATA__
neko.am
nyaa.am
be.ax
cat.ax
es.ax
eu.ax
gg.ax
mc.ax
us.ax
xy.ax
nl.ci
xx.gl
app.gp
blog.gt
de.gt
to.gt
be.gy
cc.hn
blog.kg
io.kg
jp.kg
tv.kg
uk.kg
us.kg
de.ls
at.md
de.md
jp.md
to.md
indie.porn
vxl.sh
ch.tc
me.tc
we.tc
nyan.to
at.vg
blog.vu
dev.vu
me.vu
tele.amune.org
dh.bytemark.co.uk
vm.bytemark.co.uk
hu.com
kr.com
uy.com
c.la
r.cdn77.net
ssl.origin.cdn77-secure.org
test.ru
cupcake.is
dynv6.net
staging.onred.one
mc.eu.org
filegear-au.me
fireweb.app
flap.id
flynnhosting.net
ro.im
publishproxy.com
blogspot.mr
blogspot.td
hs.zone
hs.run
herokussl.com
lon.wafaicloud.com
cloud.jelastic.open.tim.it
jelastic.tsukaeru.net
jelastic.regruhosting.ru
co.krd
krellian.net
lelux.site
cn.vu
forte.id
4u.com
001www.com
hicam.net
now-dns.top
crafting.xyz
pcloud.host
nyc.mn
cya.gg
rdv.to
ent.platform.sh
dyn53.io
id.firewalledreplit.co
wellbeingzone.eu
nodes.k8s.fr-par.scw.cloud
nodes.k8s.nl-ams.scw.cloud
nodes.k8s.pl-waw.scw.cloud
shiftedit.io
alpha.bounty-full.com
beta.bounty-full.com
privatelink.snowflake.app
dev.static.land
sites.static.land
su.paba.se
beta.tailscale.net
urown.cloud
dnsupdate.info
ybo.faith
yombo.me
ybo.party
ybo.review
ybo.science
ybo.trade
neko.am
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 33371
;neko.am.                       IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 22570
;neko.am.                       IN      SOA
nyaa.am
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 15984
;nyaa.am.                       IN      A
nyaa.am.                211     IN      A       159.65.11.121
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 64494
;nyaa.am.                       IN      SOA
nyaa.am.                900     IN      SOA     ns-1954.awsdns-52.co.uk. awsdns-hostmaster.amazon.com. 1 7200 900 1209600 86400
be.ax
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12644
;be.ax.                         IN      A
be.ax.                  1800    IN      A       34.139.60.138
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6975
;be.ax.                         IN      SOA
be.ax.                  1800    IN      SOA     ns1.digitalocean.com. hostmaster.be.ax. 1690554014 10800 3600 604800 1800
cat.ax
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 28432
;cat.ax.                                IN      A
cat.ax.                 3600    IN      A       68.183.100.217
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 28386
;cat.ax.                                IN      SOA
cat.ax.                 1800    IN      SOA     ns1.digitalocean.com. hostmaster.cat.ax. 1685257590 10800 3600 604800 1800
es.ax
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 41997
;es.ax.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 9464
;es.ax.                         IN      SOA
eu.ax
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 22906
;eu.ax.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 34216
;eu.ax.                         IN      SOA
gg.ax
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 22304
;gg.ax.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29813
;gg.ax.                         IN      SOA
gg.ax.                  3600    IN      SOA     ns1.quantum2.xyz. admin.quantum5.ca. 1684739138 7200 1800 259200 900
mc.ax
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 21400
;mc.ax.                         IN      A
mc.ax.                  300     IN      A       34.148.25.44
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23494
;mc.ax.                         IN      SOA
mc.ax.                  1800    IN      SOA     edna.ns.cloudflare.com. dns.cloudflare.com. 2316097184 10000 2400 604800 1800
us.ax
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 27160
;us.ax.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 27821
;us.ax.                         IN      SOA
xy.ax
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 37793
;xy.ax.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 54681
;xy.ax.                         IN      SOA
xy.ax.                  21512   IN      SOA     ns.inwx.de. hostmaster.inwx.de. 2022100505 10800 3600 604800 3600
nl.ci
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 18531
;nl.ci.                         IN      A
nl.ci.                  21512   IN      A       185.26.105.244
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 52325
;nl.ci.                         IN      SOA
nl.ci.                  21600   IN      SOA     ns1.netim.net. hostmaster.netim.net. 2023041001 10800 7200 604800 86400
xx.gl
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 879
;xx.gl.                         IN      A
xx.gl.                  300     IN      A       64.190.63.111
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 15870
;xx.gl.                         IN      SOA
xx.gl.                  21600   IN      SOA     ns1.sedoparking.com. hostmaster.sedo.de. 2018051601 86400 10800 604800 86400
app.gp
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 50782
;app.gp.                                IN      A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 30794
;app.gp.                                IN      SOA
app.gp.                 3600    IN      SOA     ns42.cloudns.net. support.cloudns.net. 2023072602 7200 1800 1209600 3600
blog.gt
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 28233
;blog.gt.                       IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 35805
;blog.gt.                       IN      SOA
de.gt
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6060
;de.gt.                         IN      A
de.gt.                  120     IN      A       62.216.211.166
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 47598
;de.gt.                         IN      SOA
de.gt.                  3600    IN      SOA     ns1.dynu.com. administrator.dynu.com. 12 3600 900 604800 300
to.gt
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 2265
;to.gt.                         IN      A
to.gt.                  3600    IN      A       169.47.130.75
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 20934
;to.gt.                         IN      SOA
to.gt.                  3600    IN      SOA     ns1.afraid.org. dnsadmin.afraid.org. 2303210001 86400 7200 2419200 3600
be.gy
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 49611
;be.gy.                         IN      A
be.gy.                  10800   IN      A       199.59.243.224
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 64512
;be.gy.                         IN      SOA
be.gy.                  10800   IN      SOA     ns1.bodis.com. dnsadmin.bodis.com. 2017062202 10800 3600 1209600 3600
cc.hn
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 19271
;cc.hn.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 18999
;cc.hn.                         IN      SOA
blog.kg
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 912
;blog.kg.                       IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 26335
;blog.kg.                       IN      SOA
io.kg
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 34732
;io.kg.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 39702
;io.kg.                         IN      SOA
io.kg.                  3600    IN      SOA     ns3-l2.nic.ru. dns.nic.ru. 2023030904 1440 3600 2592000 600
jp.kg
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 7788
;jp.kg.                         IN      A
jp.kg.                  33      IN      A       127.0.0.1
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 22061
;jp.kg.                         IN      SOA
tv.kg
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 34511
;tv.kg.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 22056
;tv.kg.                         IN      SOA
uk.kg
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 29907
;uk.kg.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 34703
;uk.kg.                         IN      SOA
uk.kg.                  21600   IN      SOA     ns.kg. hm.domain.kg. 200435 86400 7200 604800 86400
us.kg
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 44497
;us.kg.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 34110
;us.kg.                         IN      SOA
us.kg.                  300     IN      SOA     ns1.us.kg. admin.us.kg. 2023052177 600 180 1209600 300
de.ls
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4700
;de.ls.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60612
;de.ls.                         IN      SOA
de.ls.                  21600   IN      SOA     ns.inwx.de. hostmaster.inwx.de. 2022100707 10800 3600 604800 3600
at.md
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 8253
;at.md.                         IN      A
at.md.                  14313   IN      A       192.185.147.205
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 17472
;at.md.                         IN      SOA
at.md.                  21600   IN      SOA     ns1207.websitewelcome.com. harmonyinfotech.gmail.com. 2023072601 86400 7200 3600000 86400
de.md
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 27772
;de.md.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 59716
;de.md.                         IN      SOA
jp.md
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 54491
;jp.md.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 56532
;jp.md.                         IN      SOA
jp.md.                  3600    IN      SOA     dns.voxel.sh. dns.voxel.sh. 2023072400 14400 1800 604800 86400
to.md
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 22343
;to.md.                         IN      A
to.md.                  21600   IN      A       159.69.45.52
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 2130
;to.md.                         IN      SOA
to.md.                  3600    IN      SOA     dns.voxel.sh. dns.voxel.sh. 2023072400 14400 1800 604800 86400
indie.porn
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 35680
;indie.porn.                    IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 36284
;indie.porn.                    IN      SOA
vxl.sh
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29481
;vxl.sh.                                IN      A
vxl.sh.                 3600    IN      A       51.15.34.118
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 41822
;vxl.sh.                                IN      SOA
vxl.sh.                 1800    IN      SOA     ns1.digitalocean.com. hostmaster.vxl.sh. 1689110802 10800 3600 604800 1800
ch.tc
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 18531
;ch.tc.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 27429
;ch.tc.                         IN      SOA
me.tc
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 47103
;me.tc.                         IN      A
me.tc.                  10715   IN      A       199.59.243.224
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 42081
;me.tc.                         IN      SOA
me.tc.                  10800   IN      SOA     ns1.bodis.com. dnsadmin.bodis.com. 2017062202 10800 3600 1209600 3600
we.tc
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 36893
;we.tc.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 38602
;we.tc.                         IN      SOA
nyan.to
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 53947
;nyan.to.                       IN      A
park.io.                60      IN      A       54.172.46.232
park.io.                60      IN      A       54.156.189.193
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 20321
;nyan.to.                       IN      SOA
nyan.to.                21600   IN      SOA     a.dns.park.io. 2014070706. 28800 7200 604800 86400 3600
at.vg
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 65259
;at.vg.                         IN      A
at.vg.                  600     IN      A       5.22.145.16
at.vg.                  600     IN      A       5.22.145.121
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 40819
;at.vg.                         IN      SOA
at.vg.                  21600   IN      SOA     ns1.domaindiscount24.net. tech.key-systems.net. 2022103010 10800 3600 604800 28800
blog.vu
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 12245
;blog.vu.                       IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 31810
;blog.vu.                       IN      SOA
dev.vu
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 26584
;dev.vu.                                IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 15798
;dev.vu.                                IN      SOA
me.vu
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 31088
;me.vu.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 36127
;me.vu.                         IN      SOA
tele.amune.org
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 53666
;tele.amune.org.                        IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 10596
;tele.amune.org.                        IN      SOA
dh.bytemark.co.uk
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 4967
;dh.bytemark.co.uk.             IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 37243
;dh.bytemark.co.uk.             IN      SOA
vm.bytemark.co.uk
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 35293
;vm.bytemark.co.uk.             IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 38488
;vm.bytemark.co.uk.             IN      SOA
hu.com
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 38638
;hu.com.                                IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 52682
;hu.com.                                IN      SOA
kr.com
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 53279
;kr.com.                                IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 52938
;kr.com.                                IN      SOA
uy.com
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 9400
;uy.com.                                IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 5957
;uy.com.                                IN      SOA
c.la
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 41822
;c.la.                          IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 21692
;c.la.                          IN      SOA
r.cdn77.net
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 20552
;r.cdn77.net.                   IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 30797
;r.cdn77.net.                   IN      SOA
ssl.origin.cdn77-secure.org
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 13781
;ssl.origin.cdn77-secure.org.   IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 28588
;ssl.origin.cdn77-secure.org.   IN      SOA
test.ru
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 49525
;test.ru.                       IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 25741
;test.ru.                       IN      SOA
cupcake.is
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 52327
;cupcake.is.                    IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 10953
;cupcake.is.                    IN      SOA
dynv6.net
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 48620
;dynv6.net.                     IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 13334
;dynv6.net.                     IN      SOA
staging.onred.one
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 33406
;staging.onred.one.             IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 33723
;staging.onred.one.             IN      SOA
mc.eu.org
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 25132
;mc.eu.org.                     IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 60251
;mc.eu.org.                     IN      SOA
filegear-au.me
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 54250
;filegear-au.me.                        IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 35806
;filegear-au.me.                        IN      SOA
fireweb.app
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 40972
;fireweb.app.                   IN      A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 10501
;fireweb.app.                   IN      SOA
fireweb.app.            21600   IN      SOA     ns2.mythic-beasts.com. hostmaster.mythic-beasts.com. 2010000003 21600 7200 604800 3600
flap.id
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 45817
;flap.id.                       IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 59131
;flap.id.                       IN      SOA
flynnhosting.net
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 19116
;flynnhosting.net.              IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 14430
;flynnhosting.net.              IN      SOA
ro.im
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 17641
;ro.im.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 6849
;ro.im.                         IN      SOA
publishproxy.com
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 49246
;publishproxy.com.              IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 56654
;publishproxy.com.              IN      SOA
blogspot.mr
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 17603
;blogspot.mr.                   IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 779
;blogspot.mr.                   IN      SOA
blogspot.td
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 57597
;blogspot.td.                   IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 61752
;blogspot.td.                   IN      SOA
hs.zone
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 16606
;hs.zone.                       IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 26011
;hs.zone.                       IN      SOA
hs.run
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 55163
;hs.run.                                IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 20530
;hs.run.                                IN      SOA
herokussl.com
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 41155
;herokussl.com.                 IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 57637
;herokussl.com.                 IN      SOA
lon.wafaicloud.com
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 62739
;lon.wafaicloud.com.            IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 49642
;lon.wafaicloud.com.            IN      SOA
cloud.jelastic.open.tim.it
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 46336
;cloud.jelastic.open.tim.it.    IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 38177
;cloud.jelastic.open.tim.it.    IN      SOA
jelastic.tsukaeru.net
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 48922
;jelastic.tsukaeru.net.         IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 55351
;jelastic.tsukaeru.net.         IN      SOA
jelastic.regruhosting.ru
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 38694
;jelastic.regruhosting.ru.      IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 3223
;jelastic.regruhosting.ru.      IN      SOA
co.krd
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 43275
;co.krd.                                IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 22500
;co.krd.                                IN      SOA
krellian.net
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 58071
;krellian.net.                  IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 63549
;krellian.net.                  IN      SOA
lelux.site
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 37271
;lelux.site.                    IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 16960
;lelux.site.                    IN      SOA
cn.vu
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 57431
;cn.vu.                         IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 6369
;cn.vu.                         IN      SOA
forte.id
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 42042
;forte.id.                      IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 1552
;forte.id.                      IN      SOA
4u.com
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 7996
;4u.com.                                IN      A
4u.com.                 3503    IN      A       72.167.242.48
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 53688
;4u.com.                                IN      SOA
4u.com.                 900     IN      SOA     ns1.registry-servers.4u.com. admin.tldns.godaddy. 1690807021 1800 300 604800 1800
001www.com
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 28215
;001www.com.                    IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 35439
;001www.com.                    IN      SOA
hicam.net
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 19308
;hicam.net.                     IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 21836
;hicam.net.                     IN      SOA
now-dns.top
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 47793
;now-dns.top.                   IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 2368
;now-dns.top.                   IN      SOA
crafting.xyz
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 52811
;crafting.xyz.                  IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 33818
;crafting.xyz.                  IN      SOA
pcloud.host
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 44273
;pcloud.host.                   IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 58474
;pcloud.host.                   IN      SOA
nyc.mn
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 59747
;nyc.mn.                                IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 22926
;nyc.mn.                                IN      SOA
cya.gg
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 5100
;cya.gg.                                IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 16435
;cya.gg.                                IN      SOA
rdv.to
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 19959
;rdv.to.                                IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 45900
;rdv.to.                                IN      SOA
ent.platform.sh
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 54016
;ent.platform.sh.               IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 48868
;ent.platform.sh.               IN      SOA
dyn53.io
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 25938
;dyn53.io.                      IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 38224
;dyn53.io.                      IN      SOA
id.firewalledreplit.co
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 59499
;id.firewalledreplit.co.                IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 63268
;id.firewalledreplit.co.                IN      SOA
wellbeingzone.eu
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 53660
;wellbeingzone.eu.              IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 30288
;wellbeingzone.eu.              IN      SOA
nodes.k8s.fr-par.scw.cloud
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 849
;nodes.k8s.fr-par.scw.cloud.    IN      A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 46526
;nodes.k8s.fr-par.scw.cloud.    IN      SOA
nodes.k8s.nl-ams.scw.cloud
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 49517
;nodes.k8s.nl-ams.scw.cloud.    IN      A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 62356
;nodes.k8s.nl-ams.scw.cloud.    IN      SOA
nodes.k8s.pl-waw.scw.cloud
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 26099
;nodes.k8s.pl-waw.scw.cloud.    IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 57387
;nodes.k8s.pl-waw.scw.cloud.    IN      SOA
shiftedit.io
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 39831
;shiftedit.io.                  IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 49839
;shiftedit.io.                  IN      SOA
alpha.bounty-full.com
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 22183
;alpha.bounty-full.com.         IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 44599
;alpha.bounty-full.com.         IN      SOA
beta.bounty-full.com
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 65420
;beta.bounty-full.com.          IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 11427
;beta.bounty-full.com.          IN      SOA
privatelink.snowflake.app
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 21555
;privatelink.snowflake.app.     IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 3188
;privatelink.snowflake.app.     IN      SOA
dev.static.land
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 60032
;dev.static.land.               IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 22803
;dev.static.land.               IN      SOA
sites.static.land
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 61826
;sites.static.land.             IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 5118
;sites.static.land.             IN      SOA
su.paba.se
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 25659
;su.paba.se.                    IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 37958
;su.paba.se.                    IN      SOA
beta.tailscale.net
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 39243
;beta.tailscale.net.            IN      A
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 18213
;beta.tailscale.net.            IN      SOA
urown.cloud
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 17741
;urown.cloud.                   IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 12884
;urown.cloud.                   IN      SOA
dnsupdate.info
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 27719
;dnsupdate.info.                        IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 6903
;dnsupdate.info.                        IN      SOA
ybo.faith
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 28149
;ybo.faith.                     IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 57562
;ybo.faith.                     IN      SOA
yombo.me
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 46454
;yombo.me.                      IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 23634
;yombo.me.                      IN      SOA
ybo.party
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 42212
;ybo.party.                     IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 42525
;ybo.party.                     IN      SOA
ybo.review
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 27321
;ybo.review.                    IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 22428
;ybo.review.                    IN      SOA
ybo.science
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 44913
;ybo.science.                   IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 24487
;ybo.science.                   IN      SOA
ybo.trade
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 12904
;ybo.trade.                     IN      A
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 27844
;ybo.trade.                     IN      SOA

@arxenix
Copy link

arxenix commented Oct 27, 2023

hi, I am the owner of cat.ax and would like it to remain on the PSL, as I (plan to) offer arbitrary user-controlled subdomains.

@007hacky007
Copy link
Contributor

We're the owners of

    r.cdn77.net
    ssl.origin.cdn77-secure.org

And these are still in active use. Do not remove them.

There's proper _psl TXT record in the DNS for both domains as well.

 $ dig TXT _psl.r.cdn77.net

; <<>> DiG 9.10.6 <<>> TXT _psl.r.cdn77.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 13689
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;_psl.r.cdn77.net.		IN	TXT

;; ANSWER SECTION:
_psl.r.cdn77.net.	60	IN	TXT	"https://github.com/publicsuffix/list/pull/15"

;; Query time: 256 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Wed Jan 10 11:59:21 CET 2024
;; MSG SIZE  rcvd: 102

$ dig TXT _psl.ssl.origin.cdn77-secure.org

; <<>> DiG 9.10.6 <<>> TXT _psl.ssl.origin.cdn77-secure.org
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 56182
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;_psl.ssl.origin.cdn77-secure.org. IN	TXT

;; ANSWER SECTION:
_psl.ssl.origin.cdn77-secure.org. 60 IN	TXT	"https://github.com/publicsuffix/list/pull/15"

;; Query time: 249 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Wed Jan 10 11:59:44 CET 2024
;; MSG SIZE  rcvd: 118

@mozfreddyb
Copy link
Contributor

As much as I appreciate the idea this pull request, I think we need to solve expiry differently. I think we should close this and work on an expiry proposal rather than discussing individual entries here.

@mozfreddyb mozfreddyb closed this Jan 11, 2024
List Add/Mod/Del automation moved this from To-Do to Done or Won't Jan 11, 2024
@dnsguru
Copy link
Member

dnsguru commented Jan 11, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
MAY DESERVE SECURITY REVIEW This is a PR that might benefit from a re-review 🩺 pending-validation Something needs to be validated
Projects
List Add/Mod/Del
  
Done or Won't
Development

Successfully merging this pull request may close these issues.

Some NXDomain entries that should be de-listed Coordination of Amazon submissions to the PSL
6 participants