Only recently we have realized potential of DNS servers as security tools says Cricket Liu at Infoblox
As I’m fond of saying, back in the early days of BIND name servers—when I got my start in DNS—they had a whopping two security features: They didn’t accept responses from IP