All about Networking

Bufferbloat and Internet Speed Test

https://www.waveform.com/tools/bufferbloat

Bufferbloat | Network Testing | Networking | Performance

Waveform's Bufferbloat test measures how much latency rises when your connection is saturated by uploads or downloads.

The test runs a baseline latency check, then repeats latency while performing a download and an upload speed test to compare the differences.

The page explains bufferbloat, gives pre-test advice (disable heavy tasks; use a wired connection when possible), and shows how results are graded and interpreted.

It lists routers and router features (SQM, DumaOS, IQrouter, Ubiquiti) that help mitigate bufferbloat, with shopping links and brief notes.


DNS — The Phonebook That Isn't

https://toolkit.whysonil.dev/how-it-works/dns/

DNS | Networking | Protocols | Security

WhySoNil's DNS guide explains DNS as the internet's distributed "phonebook", designed for speed and scale.

It covers transport (UDP on port 53 with TCP fallback), namespace delegation (root → TLD → authoritative), and the importance of caching and TTL.

It details zone files, common record types (A, AAAA, CNAME, MX, TXT, NS, SOA, CAA, SRV), and glue records.

It explains performance and resilience techniques such as anycast and multi-layer caching.

It summarizes security: DNSSEC for integrity and DoT/DoH/DoQ for encrypted transport, with practical trade-offs.

It includes practical debugging commands and tools (dig, dig +trace, dig +dnssec, nslookup, dog) and pointers to DNSViz and intoDNS for visualization.

Key takeaways:

  • DNS is optimized for small, fast UDP queries; TCP is the fallback for large responses.
  • TTL-driven caching scales DNS but requires careful TTL management during changes.
  • DNSSEC provides integrity, not privacy; DoH/DoT/DoQ add privacy but shift trust to providers.
  • Use dig and dig +trace to diagnose delegation, caching, and DNSSEC issues.

The page also includes a short self-check quiz and links to RFCs and Cloudflare learning for further reading.


DNSSEC Debugger (Verisign Labs)

https://dnssec-debugger.verisignlabs.com/

DNSSEC | Diagnostic Tools | Networking

The DNSSEC Debugger is a web-based diagnostic tool from VeriSign Labs that validates DNSSEC configurations for a domain. It runs iterative DNS resolution and verifies the DNSSEC chain of trust from the root down to the authoritative zone.

  • Enter a domain to run checks that validate DNSKEY/DS consistency.
  • Verifies RRSIG validity and expiry, algorithm mismatches, and missing signatures.
  • Shows a step-by-step resolution trace with per-step status and diagnostic messages.
  • Provides "Advanced options" to tune queries and inspect raw DNS responses.
  • Offers actionable hints for common misconfigurations such as key rollovers or absent DS records.

Use it to quickly locate where a DNSSEC chain breaks and to gather concrete debugging details for fixes.