auth-unknown-zone-refused
Purpose
Queries for names outside any zone the authoritative peer loads usually come back REFUSED. With Conduit in front, clients should see that same refusal — Conduit does not turn it into NXDOMAIN, NODATA, or a success.
How it works
- The peer loads only fixture zone
example.test. - A client asks Conduit for
no.such.zone.testA (no matching zone). - The reply must be REFUSED and match a direct query to the peer.
Outcomes
| Outcome | Meaning for operators |
|---|---|
| pass | Through Conduit, the out-of-zone query is REFUSED, matching the peer. |
| fail | Unexpected success or another rcode, or Conduit disagreed with querying the peer directly. |
| skip | Peer is not authoritative for this matrix (or profile out of scope). |
| characterized | Not used for this case today. If it appeared, it would mean a documented peer-specific quirk rather than a Conduit regression. |
Matrix: peer (by publisher)
Suites: full
Oracles: property, parity