I'm trying to setup a new external DNS/Nameserver that queries multiple DirectAdmin servers. I've used BIND9 with forwarders to set this up and it works fine (with recursion enabled). The forwarders are only IP's of servers where i host my websites on (no Google DNS or something). And when i check http://openresolver.com/?ip=dns1.chaseweb.nl it says that it isn't vulnerable to DNS Amplification attacks.

I would like to know if this setup is safe enough to use in production or is it still vulnerable to DNS Amplification attacks or other attacks?

(it's now on a local box but i will move it to DO when it's safe/ready)


As long as your DNS server responds only to domains that you host, you should be fine. It's basically the same as using DirectAdmin's authoritative DNS servers directly, except with a proxy in the middle. That should be safe enough, as long as you:

  1. Only allow it to forward requests to your own authoritative DNS servers
  2. Disable recursion on the said DNS servers.
