Chain Query requests in DNS

The information below is for an old version of the document
Document Type Expired Internet-Draft (dnsop WG)
Last updated 2015-09-10 (latest revision 2015-03-09)
Replaces draft-wouters-edns-chain-query
Stream IETF
Intended RFC status Experimental
Expired & archived
pdf htmlized (tools) htmlized bibtex
Stream WG state WG Document
Document shepherd Tim Wicinski
IESG IESG state Expired
Consensus Boilerplate Unknown
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


This document defines an EDNS0 extension that can be used by a security-aware validating Resolver configured as a Forwarder to send a single query, requesting a complete validation path along with the regular query answer. The reduction in queries lowers the latency. This extension requries the use of source IP verified transport such as TCP or UDP with DNS-COOKIES so it cannot be abused in amplification attacks.


Paul Wouters (

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)