DNS

how-does-dns-work.gmi

host your own zones

recursive server for your clients

Bedtime Reading

External

tunnel IPv4 through DNS

DNSSEC is perhaps too complicated, though one can workaround the issue by first doing sanity checks on the input. So much for "be permissive in what you accept":

DNSSEC packet DoS

Details Matter

From June 30, 2020 until January 14, 2025, one of the core Internet servers that MasterCard uses to direct traffic for portions of the mastercard.com network was misnamed. MasterCard.com relies on five shared Domain Name System (DNS) servers at the Internet infrastructure provider Akamai [DNS acts as a kind of Internet phone book, by translating website names to numeric Internet addresses that are easier for computers to manage].
All of the Akamai DNS server names that MasterCard uses are supposed to end in “akam.net” but one of them was misconfigured to rely on the domain “akam.ne.”

https://krebsonsecurity.com/2025/01/mastercard-dns-error-went-unnoticed-for-years/