Security & Threat Intelligence · 25.07.2026, 15:29 UTC
More Odd DNS Records: NIMLOC, (Tue, Jul 7th)
| Schweregrad | info |
|---|---|
| Kategorie | Security & Threat Intelligence |
| Quelle | SANS Internet Storm Center ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Yesterday, I talked about NAPTR records and how they are related to RCS. But there is another "odd" record that shows up in my DNS logs. This one isn't new, but I don't think I ever covered it: NIMLOC. At least that is what Zeek calls it. But let's see what it is all about.
At first, it looks like NIMLOC records are no longer used. Google's AI overview explains: "A NIMLOC (Nimrod Locator) DNS record is an obsolete resource record type (Type 32) originally designed for the Nimrod routing architecture to map names to network locators. Because Nimrod was an experimental protocol, NIMLOC records are considered historic and are not used in modern, standard network operations."
While I do have one or the other odd IOT device in my network, I doubt any of them speak "Nimrod". On the other hand, the queries originate from my macOS systems. This turns out to be an older standard, replaced by a newer (but still old) standard, with the newer standard becoming obsolete before the even older standard is phased out.
DNS defines several resource record types. The official list is maintained by IANA [1] and I am including a sample below:
TYPE Value Meaning References A 1 IPv4 Address RFC1035 NS 2 Name Server RFC1035 PTR 12 Domain Name Pointer RFC1035 MX 15 Mail Server RFC1035 TXT 16 Text String RFC1035 AAAA 28 IPv6 Address RFC3596 NIMLOC 32 Nimrod Locator (no RFC) SRV 33 Server Selection RFC2782 NAPTR 35 Naming Authority Pointer RFC3403
There is a range of unassigned RR types, so one would think …