In this chapter, we looked at the exigencies of handling Distributed Denial-of-Service (DDoS) attacks against your DNS infrastructure. We examined several aspects of what you can do when they happen, at both the individual domain holder and aggregate provider level.
I can never say it too often, so I'll say it again here: DDoS mitigation is an arms race, and you are usually fighting the last war. The next attack will be bigger, and the next attack will be harder to mitigate, so if you absolutely, positively must have 100% DNS availability all the time, the way to achieve that is to use multiple DNS providers or systems and have a coherent methodology for deploying your zone data across them and have the ability to switch between them as the need arises.