Skip to content

pdns-recursor-rd0-refused

Purpose

When Conduit forwards to PowerDNS Recursor, a client query with the recursion-desired bit cleared (RD=0) can receive REFUSED for a name the Recursor would answer successfully if RD were set — that is Recursor’s default policy for non-recursive queries, not a Conduit refusal. Operators should see that same REFUSED through Conduit (Conduit does not invent an answer or rewrite the rcode).

How it works

  1. The Recursor under test is given a local auth-zone name that answers A successfully when RD=1.
  2. The client queries that name via Conduit with RD cleared (for example dig +nord).
  3. The response must be REFUSED and must match a direct query to the Recursor with the same flags.

Outcomes

Outcome Meaning for operators
pass Not expected for this case; a matching result is reported as characterized.
fail Through Conduit the client did not get REFUSED, or Conduit’s answer disagreed with querying the Recursor directly.
skip Peer is not PowerDNS Recursor for this matrix (or profile out of scope).
characterized Expected: RD=0 yields REFUSED through Conduit, matching the Recursor’s own reply.

Matrix: peer (by publisher)

Suites: full

Oracles: property, parity, differential