diff --git a/dns_compare.py b/dns_compare.py index 6fe9b1c..84d3ed3 100755 --- a/dns_compare.py +++ b/dns_compare.py @@ -111,8 +111,37 @@ def perform_query(full_domain, ns, record_type, timeout): if args.verbose: print(f"[DEBUG] UDP Response: Answer={len(r.answer)} RRsets, TC flag: {bool(r.flags & flags.TC)}", file=sys.stderr) + # Check if UDP returned ETPA error - if so, try TCP + udp_rcode = r.rcode() + udp_rcode_name = rcode.to_text(udp_rcode) + if udp_rcode_name == "ETPA": + if args.verbose: + print(f"[DEBUG] UDP returned ETPA, retrying with TCP...", file=sys.stderr) + try: + r = query.tcp(q, ns, timeout=timeout) + protocol_used = "TCP" + if args.verbose: + print(f"[DEBUG] TCP Response: Answer={len(r.answer)} RRsets, TC flag: {bool(r.flags & flags.TC)}", file=sys.stderr) + # If TCP also returned ETPA, try TLS + tcp_rcode = r.rcode() + tcp_rcode_name = rcode.to_text(tcp_rcode) + if tcp_rcode_name == "ETPA": + if args.verbose: + print(f"[DEBUG] TCP also returned ETPA, retrying with TLS...", file=sys.stderr) + r = query.tls(q, ns, timeout=timeout) + protocol_used = "TLS" + if args.verbose: + print(f"[DEBUG] TLS Response: Answer={len(r.answer)} RRsets, TC flag: {bool(r.flags & flags.TC)}", file=sys.stderr) + except Exception as tcp_error: + # Fall back to TLS if TCP fails + if args.verbose: + print(f"[DEBUG] TCP failed ({tcp_error}), trying TLS...", file=sys.stderr) + r = query.tls(q, ns, timeout=timeout) + protocol_used = "TLS" + if args.verbose: + print(f"[DEBUG] TLS Response: Answer={len(r.answer)} RRsets, TC flag: {bool(r.flags & flags.TC)}", file=sys.stderr) # If UDP returns truncated, retry with TCP - if r.flags & flags.TC: + elif r.flags & flags.TC: if args.verbose: print(f"[DEBUG] UDP Response truncated (TC flag set), retrying with TCP...", file=sys.stderr) try: @@ -137,6 +166,16 @@ def perform_query(full_domain, ns, record_type, timeout): protocol_used = "TCP" if args.verbose: print(f"[DEBUG] TCP Response: Answer={len(r.answer)} RRsets, TC flag: {bool(r.flags & flags.TC)}", file=sys.stderr) + # If TCP returned ETPA, try TLS + tcp_rcode = r.rcode() + tcp_rcode_name = rcode.to_text(tcp_rcode) + if tcp_rcode_name == "ETPA": + if args.verbose: + print(f"[DEBUG] TCP returned ETPA, retrying with TLS...", file=sys.stderr) + r = query.tls(q, ns, timeout=timeout) + protocol_used = "TLS" + if args.verbose: + print(f"[DEBUG] TLS Response: Answer={len(r.answer)} RRsets, TC flag: {bool(r.flags & flags.TC)}", file=sys.stderr) except Exception as tcp_error: # Fall back to TLS if TCP fails if args.verbose: