As stated earlier in Chapter 12, Nameserver Considerations, if you're going to be offering DNS services, you're going to get hit. It's a matter of when, not if. The first time it happened to easyDNS, we were completely oblivious to the spectre of DDoS attacks and our infrastructure absolutely pancaked under the hit. It knocked all of our nameservers completely off the internet and and most of our customers went offline with them.
Since that day, devising ways as a DNS operator to withstand and parry DDoS attacks has become somewhat of an obsession. Again, some of the decisions I made pursuant to Chapter 12, Nameserver Considerations, came back to haunt me. Some of them still do today. That's why I said that whatever you decide in that section, think about it carefully. You'll be living with some of those decisions...