Sign in
P-9ProposedGlobal, Registry Council

Mirrors

Version
v1
In force since
Not yet
Next review
At adoption
Snapshot
None yet
Adopted by
Proposed for founding adoption
Signature
At adoption
Log entry
Not appended yet
Binding text
English

Proposed, not in force

Open for comment until 28 October 2026, 00:00 UTC. Nothing here binds anyone until it is adopted.

1

Scope

1.1
Bindingp9-c1

This policy binds every mirror enrolled with GOpenCDR, in the open community tier and in the certified tier, whatever its role: public resolver, private resolver, authoritative secondary or full zone mirror.

2

Conformance

2.1
Enforced rulep9-c2Not enforced yet

A mirror joins a tier, and stays in it, only while it passes the automated conformance suite: it validates DNSSEC, serves only zone versions its agent has verified, and enforces P-1 2.1. It never rewrites NXDOMAIN, injects answers, strips DNSSEC or sends EDNS Client Subnet upstream. GOpenCDR probes it continuously; a mirror that fails leaves its tier at once and returns once it passes again.

Rule mirror.conformance.

2.2
Enforced settingp9-c3Not enforced yet

A mirror applies a withdrawal within 1 hourfloor and serves the current serial within 15 minutesfloor.

2.3
Bindingp9-c4

A mirror runs a current signed release of the agent, which checks the signature of every update before installing it, and serves GOpenCDR zones only from a resolver the agent manages.

3

Public resolvers

3.1
Enforced rulep9-c5Not enforced yet

A public resolver runs behind response rate limiting, with minimal ANY answers as RFC 8482 describes, DNS cookies and caps on amplification, and applies source address validation where the network allows it.

Rule mirror.open_resolver_safety.

4

Logging

4.1
Enforced settingp9-c6Not enforced yet

A mirror in the default pool keeps no log that links queries to client addresses for longer than 24 hoursfixed, and then only for debugging, and reports only aggregate statistics with minimum counts.

4.2
Guidancep9-c7

A mirror outside the default pool should follow 4.1 as well, and publish its own privacy information if it is open to the public.

5

The certified tier

5.1
Bindingp9-c8

A certified mirror, which joins the default pool, signs the operator agreement and a data processing agreement.

5.2
Enforced settingp9-c9Not enforced yet

Tier 0 audits every certified mirror remotely every 12 monthsfixed against a published checklist, beside continuous probing and unannounced spot checks.

6

Zone files

6.1
Bindingp9-c10

A TLD zone file goes to an enrolled mirror only so that it can serve and verify it. It is never published, passed on, sold, mined or used to market to registrants, and every copy is deleted when the enrolment ends. The root zone is public. Who may receive a TLD's zone is set under P-4 4.3.

7

Suspension

7.1
Bindingp9-c11

Tier 0 may suspend an enrolment at once where a mirror fails conformance, serves wrong data, is compromised or used for abuse, or where a court, an authority or a collision with the IANA namespace requires it. The operator is told why and may ask for a review.