12. Security Considerations
This memo does not introduce any new security considerations. However, it clarifies some aspects of the DNS that are relevant to security.
The use of the TC bit is relevant to security, as it can be used to force a client to use TCP, which is more expensive for the server. A server must not set the TC bit in a response unless the response has been truncated. A client must not send a query with the TC bit set.
The use of CNAME RRs is relevant to security, as a CNAME RR can be used to redirect a query to a different name. A server must not allow a CNAME RR to point to itself, directly or indirectly.
The use of MX and NS records is relevant to security, as they can be used to redirect mail or to delegate authority. A server must not allow an MX or NS record to point to an alias.
The use of the source address of a reply is relevant to security, as it can be used to filter out fake responses. A server must use the destination address of the query as the source address of the reply for UDP.
DNSSEC [RFC2065] provides cryptographic authentication of DNS data, and is the recommended way to secure the DNS. This memo does not address DNSSEC directly, but the clarifications in this memo are compatible with DNSSEC.