Do not use recursion on this domain

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I would like to know what you guys are thinking about the option below in DNS
“Do not use recursion on this domain” on the DNS setting.

The option is there for

Don’t let your internal servers roam the Internet looking for name servers.(
Bill Boswell), by the way Bill Boswell has always been one of the best in my
eyes for Exchange and active directory I do enjoy his books a lot.
http://redmondmag.com/features/article.asp?EditorialsID=413

So the point I am trying to make is,

If ISP DNS servers fail, or wherever we are forwarding for internet name
resolution, we do bigger issues to worry about.

If this happens it seems to be still better option to do recursive lookup to
the root server for internet name resolution even it will be many hops and
slow response, rather than giving no answer

any toughts?
--
Oz Ozugurlu
MVP (Exchange)
MCITP (EMA), MCITP (EA),MCITP (SA)
MCSE 2003, M+, S+, MCDST
Security+, Project +, Server +


oz@xxxxxxxxxx
http://smtp25.blogspot.com (Blog)
.



Relevant Pages

  • Re: How Secure is ".Local?"
    ... > dozen servers and ~500 websites/public domains. ... Shadow DNS ... Is your DC on the Internet? ... >>It is not going to provide your zone info to anyone ...
    (microsoft.public.win2000.dns)
  • RE: New Forest - Old Domain - Plus DMZ - Help Please
    ... Make sure Windows XP client should use the AD DNS ... The Cert should match the name in Internet. ... New Forest - Old Domain - Plus DMZ - Help Please ... vast majority of our inside production equipment is 2003 servers and XP ...
    (microsoft.public.windows.server.migration)
  • Re: Active Directory and child DNS Zone
    ... > Our internal and external DNS domains are both the same - mycompany.com. ... > hosts our external domain and it only contains entries for our web servers ... >>> but the test bed isn't a true picture (no internet access to test VPN, ...
    (microsoft.public.windows.server.dns)
  • Re: DNS design questions
    ... We're a medium size college campus with about 10,000 users and the CIO wants to have DNS locally housed. ... only a hand full to a few dozen max "Internet servers" while ... how big of a security issue really is allowing the "external" DNS server pull a zone transfer from an internal one? ...
    (microsoft.public.windows.server.dns)
  • Re: How Secure is ".Local?"
    ... dozen servers and ~500 websites/public domains. ... I'm weighing the importance of split-brain DNS ... >It is not going to provide your zone info to anyone ... >on the Internet since local is NOT a zone in the ...
    (microsoft.public.win2000.dns)