>>> $ dig -b @ c.ns.secunia.com. +short
> Yes, but i'm a little bit baffled that identical records are returned.
> Does unbound cache it this way or are the records subtil different?

Unbound just returns what the authoritative nameserver sent.

Duplicate A records like this are often produced by djbdns' tinydns-data
tool when its built-in shortcuts are used, e.g. multiple "&" records
with address, which generate NS + A records.


would produce 1 NS record for example.{org,com,net} each and 3 A records
for ns1.example.org.

> Bind 9.7 only provide only one record for the same query.

BIND removes duplicate nameserver addresses from responses, it seems.


JFTR, when using tinydns, I usually advise not to use the macros and
stick to one output record per line, ie. use "Z", "&" and "+" instead of
a single "." and define all A records explicitly. It may be neat to save
a few bytes per zone but it can be difficult to trace problems. And I
don't like most of the defaults.

(yes, talking about djbdns syntax feels a bit like speaking Esperanto ;)

