| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | package file
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | import (
 | 
					
						
							|  |  |  | 	"sort"
 | 
					
						
							|  |  |  | 	"strings"
 | 
					
						
							|  |  |  | 	"testing"
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-09-07 11:10:16 +01:00
										 |  |  | 	"github.com/miekg/coredns/middleware/pkg/dnsrecorder"
 | 
					
						
							| 
									
										
										
										
											2016-04-11 07:56:38 +01:00
										 |  |  | 	"github.com/miekg/coredns/middleware/test"
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 
 | 
					
						
							|  |  |  | 	"github.com/miekg/dns"
 | 
					
						
							|  |  |  | 	"golang.org/x/net/context"
 | 
					
						
							|  |  |  | )
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-04-11 07:56:38 +01:00
										 |  |  | var wildcardTestCases = []test.Case{
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 	{
 | 
					
						
							| 
									
										
										
										
											2016-03-31 09:25:22 +00:00
										 |  |  | 		Qname: "wild.dnssex.nl.", Qtype: dns.TypeTXT,
 | 
					
						
							|  |  |  | 		Answer: []dns.RR{
 | 
					
						
							| 
									
										
										
										
											2016-04-11 07:56:38 +01:00
										 |  |  | 			test.TXT(`wild.dnssex.nl.	1800	IN	TXT	"Doing It Safe Is Better"`),
 | 
					
						
							| 
									
										
										
										
											2016-03-31 09:25:22 +00:00
										 |  |  | 		},
 | 
					
						
							| 
									
										
										
										
											2016-12-07 20:37:29 +00:00
										 |  |  | 		Ns: dnssexAuth[:len(dnssexAuth)-1], // remove RRSIG on the end
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 	},
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | 	{
 | 
					
						
							|  |  |  | 		Qname: "a.wild.dnssex.nl.", Qtype: dns.TypeTXT,
 | 
					
						
							|  |  |  | 		Answer: []dns.RR{
 | 
					
						
							|  |  |  | 			test.TXT(`a.wild.dnssex.nl.	1800	IN	TXT	"Doing It Safe Is Better"`),
 | 
					
						
							|  |  |  | 		},
 | 
					
						
							| 
									
										
										
										
											2016-12-07 20:37:29 +00:00
										 |  |  | 		Ns: dnssexAuth[:len(dnssexAuth)-1], // remove RRSIG on the end
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | 	},
 | 
					
						
							| 
									
										
										
										
											2016-03-31 09:25:22 +00:00
										 |  |  | 	{
 | 
					
						
							|  |  |  | 		Qname: "wild.dnssex.nl.", Qtype: dns.TypeTXT, Do: true,
 | 
					
						
							|  |  |  | 		Answer: []dns.RR{
 | 
					
						
							| 
									
										
										
										
											2016-04-11 07:56:38 +01:00
										 |  |  | 			test.RRSIG("wild.dnssex.nl.	1800	IN	RRSIG	TXT 8 2 1800 20160428190224 20160329190224 14460 dnssex.nl. FUZSTyvZfeuuOpCm"),
 | 
					
						
							|  |  |  | 			test.TXT(`wild.dnssex.nl.	1800	IN	TXT	"Doing It Safe Is Better"`),
 | 
					
						
							| 
									
										
										
										
											2016-03-31 09:25:22 +00:00
										 |  |  | 		},
 | 
					
						
							| 
									
										
										
										
											2016-12-07 20:37:29 +00:00
										 |  |  | 		Ns: append([]dns.RR{
 | 
					
						
							| 
									
										
										
										
											2016-11-06 08:32:07 +00:00
										 |  |  | 			test.NSEC("a.dnssex.nl.	14400	IN	NSEC	www.dnssex.nl. A AAAA RRSIG NSEC"),
 | 
					
						
							|  |  |  | 			test.RRSIG("a.dnssex.nl.	14400	IN	RRSIG	NSEC 8 3 14400 20160428190224 20160329190224 14460 dnssex.nl. S+UMs2ySgRaaRY"),
 | 
					
						
							| 
									
										
										
										
											2016-12-07 20:37:29 +00:00
										 |  |  | 		}, dnssexAuth...),
 | 
					
						
							| 
									
										
										
										
											2016-04-11 07:56:38 +01:00
										 |  |  | 		Extra: []dns.RR{test.OPT(4096, true)},
 | 
					
						
							| 
									
										
										
										
											2016-03-31 09:25:22 +00:00
										 |  |  | 	},
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | 	{
 | 
					
						
							|  |  |  | 		Qname: "a.wild.dnssex.nl.", Qtype: dns.TypeTXT, Do: true,
 | 
					
						
							|  |  |  | 		Answer: []dns.RR{
 | 
					
						
							|  |  |  | 			test.RRSIG("a.wild.dnssex.nl.	1800	IN	RRSIG	TXT 8 2 1800 20160428190224 20160329190224 14460 dnssex.nl. FUZSTyvZfeuuOpCm"),
 | 
					
						
							|  |  |  | 			test.TXT(`a.wild.dnssex.nl.	1800	IN	TXT	"Doing It Safe Is Better"`),
 | 
					
						
							| 
									
										
										
										
											2016-03-31 09:25:22 +00:00
										 |  |  | 		},
 | 
					
						
							| 
									
										
										
										
											2016-12-07 20:37:29 +00:00
										 |  |  | 		Ns: append([]dns.RR{
 | 
					
						
							| 
									
										
										
										
											2016-11-06 08:32:07 +00:00
										 |  |  | 			test.NSEC("a.dnssex.nl.	14400	IN	NSEC	www.dnssex.nl. A AAAA RRSIG NSEC"),
 | 
					
						
							|  |  |  | 			test.RRSIG("a.dnssex.nl.	14400	IN	RRSIG	NSEC 8 3 14400 20160428190224 20160329190224 14460 dnssex.nl. S+UMs2ySgRaaRY"),
 | 
					
						
							| 
									
										
										
										
											2016-12-07 20:37:29 +00:00
										 |  |  | 		}, dnssexAuth...),
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | 		Extra: []dns.RR{test.OPT(4096, true)},
 | 
					
						
							|  |  |  | 	},
 | 
					
						
							|  |  |  | 	// nodata responses
 | 
					
						
							|  |  |  | 	{
 | 
					
						
							|  |  |  | 		Qname: "wild.dnssex.nl.", Qtype: dns.TypeSRV,
 | 
					
						
							|  |  |  | 		Ns: []dns.RR{
 | 
					
						
							|  |  |  | 			test.SOA(`dnssex.nl.	1800	IN	SOA	linode.atoom.net. miek.miek.nl. 1459281744 14400 3600 604800 14400`),
 | 
					
						
							| 
									
										
										
										
											2016-03-31 09:25:22 +00:00
										 |  |  | 		},
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | 	},
 | 
					
						
							|  |  |  | 	{
 | 
					
						
							|  |  |  | 		Qname: "wild.dnssex.nl.", Qtype: dns.TypeSRV, Do: true,
 | 
					
						
							|  |  |  | 		Ns: []dns.RR{
 | 
					
						
							| 
									
										
										
										
											2016-11-05 14:39:49 +00:00
										 |  |  | 			// TODO(miek): needs closest encloser proof as well? This is the wrong answer
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | 			test.NSEC(`*.dnssex.nl.	14400	IN	NSEC	a.dnssex.nl. TXT RRSIG NSEC`),
 | 
					
						
							| 
									
										
										
										
											2016-12-07 20:37:29 +00:00
										 |  |  | 			test.RRSIG(`*.dnssex.nl.	14400	IN	RRSIG	NSEC 8 2 14400 20160428190224 20160329190224 14460 dnssex.nl. os6INm6q2eXknD5z8TaaDOV+Ge/Ko+2dXnKP+J1fqJzafXJVH1F0nDrcXmMlR6jlBHA=`),
 | 
					
						
							|  |  |  | 			test.RRSIG(`dnssex.nl.	1800	IN	RRSIG	SOA 8 2 1800 20160428190224 20160329190224 14460 dnssex.nl. CA/Y3m9hCOiKC/8ieSOv8SeP964Bq++lyH8BZJcTaabAsERs4xj5PRtcxicwQXZiF8fYUCpROlUS0YR8Cdw=`),
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | 			test.SOA(`dnssex.nl.	1800	IN	SOA	linode.atoom.net. miek.miek.nl. 1459281744 14400 3600 604800 14400`),
 | 
					
						
							|  |  |  | 		},
 | 
					
						
							|  |  |  | 		Extra: []dns.RR{test.OPT(4096, true)},
 | 
					
						
							|  |  |  | 	},
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | }
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-12-07 20:37:29 +00:00
										 |  |  | var dnssexAuth = []dns.RR{
 | 
					
						
							|  |  |  | 	test.NS("dnssex.nl.	1800	IN	NS	linode.atoom.net."),
 | 
					
						
							|  |  |  | 	test.NS("dnssex.nl.	1800	IN	NS	ns-ext.nlnetlabs.nl."),
 | 
					
						
							|  |  |  | 	test.NS("dnssex.nl.	1800	IN	NS	omval.tednet.nl."),
 | 
					
						
							|  |  |  | 	test.RRSIG("dnssex.nl.	1800	IN	RRSIG	NS 8 2 1800 20160428190224 20160329190224 14460 dnssex.nl. dLIeEvP86jj5ndkcLzhgvWixTABjWAGRTGQsPsVDFXsGMf9TGGC9FEomgkCVeNC0="),
 | 
					
						
							|  |  |  | }
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-03-31 09:25:22 +00:00
										 |  |  | func TestLookupWildcard(t *testing.T) {
 | 
					
						
							| 
									
										
										
										
											2016-09-23 09:14:12 +01:00
										 |  |  | 	zone, err := Parse(strings.NewReader(dbDnssexNLSigned), testzone1, "stdin")
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 	if err != nil {
 | 
					
						
							| 
									
										
										
										
											2016-11-05 14:39:49 +00:00
										 |  |  | 		t.Fatalf("Expect no error when reading zone, got %q", err)
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 	}
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-04-11 07:56:38 +01:00
										 |  |  | 	fm := File{Next: test.ErrorHandler(), Zones: Zones{Z: map[string]*Zone{testzone1: zone}, Names: []string{testzone1}}}
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 	ctx := context.TODO()
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-03-31 09:25:22 +00:00
										 |  |  | 	for _, tc := range wildcardTestCases {
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 		m := tc.Msg()
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-09-07 11:10:16 +01:00
										 |  |  | 		rec := dnsrecorder.New(&test.ResponseWriter{})
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 		_, err := fm.ServeDNS(ctx, rec, m)
 | 
					
						
							|  |  |  | 		if err != nil {
 | 
					
						
							| 
									
										
										
										
											2016-11-05 14:39:49 +00:00
										 |  |  | 			t.Errorf("Expected no error, got %v\n", err)
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 			return
 | 
					
						
							|  |  |  | 		}
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-09-07 11:10:16 +01:00
										 |  |  | 		resp := rec.Msg
 | 
					
						
							| 
									
										
										
										
											2016-04-11 07:56:38 +01:00
										 |  |  | 		sort.Sort(test.RRSet(resp.Answer))
 | 
					
						
							|  |  |  | 		sort.Sort(test.RRSet(resp.Ns))
 | 
					
						
							|  |  |  | 		sort.Sort(test.RRSet(resp.Extra))
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-04-11 07:56:38 +01:00
										 |  |  | 		if !test.Header(t, tc, resp) {
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 			t.Logf("%v\n", resp)
 | 
					
						
							|  |  |  | 			continue
 | 
					
						
							|  |  |  | 		}
 | 
					
						
							| 
									
										
										
										
											2016-04-11 07:56:38 +01:00
										 |  |  | 		if !test.Section(t, tc, test.Answer, resp.Answer) {
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 			t.Logf("%v\n", resp)
 | 
					
						
							|  |  |  | 		}
 | 
					
						
							| 
									
										
										
										
											2016-04-11 07:56:38 +01:00
										 |  |  | 		if !test.Section(t, tc, test.Ns, resp.Ns) {
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 			t.Logf("%v\n", resp)
 | 
					
						
							|  |  |  | 		}
 | 
					
						
							| 
									
										
										
										
											2016-04-11 07:56:38 +01:00
										 |  |  | 		if !test.Section(t, tc, test.Extra, resp.Extra) {
 | 
					
						
							| 
									
										
										
										
											2016-03-29 21:25:06 +01:00
										 |  |  | 			t.Logf("%v\n", resp)
 | 
					
						
							|  |  |  | 		}
 | 
					
						
							|  |  |  | 	}
 | 
					
						
							|  |  |  | }
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | var wildcardDoubleTestCases = []test.Case{
 | 
					
						
							|  |  |  | 	{
 | 
					
						
							|  |  |  | 		Qname: "wild.w.example.org.", Qtype: dns.TypeTXT,
 | 
					
						
							|  |  |  | 		Answer: []dns.RR{
 | 
					
						
							|  |  |  | 			test.TXT(`wild.w.example.org. IN	TXT	"Wildcard"`),
 | 
					
						
							|  |  |  | 		},
 | 
					
						
							| 
									
										
										
										
											2016-12-07 20:37:29 +00:00
										 |  |  | 		Ns: exampleAuth,
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | 	},
 | 
					
						
							|  |  |  | 	{
 | 
					
						
							|  |  |  | 		Qname: "wild.c.example.org.", Qtype: dns.TypeTXT,
 | 
					
						
							|  |  |  | 		Answer: []dns.RR{
 | 
					
						
							|  |  |  | 			test.TXT(`wild.c.example.org. IN	TXT	"c Wildcard"`),
 | 
					
						
							|  |  |  | 		},
 | 
					
						
							| 
									
										
										
										
											2016-12-07 20:37:29 +00:00
										 |  |  | 		Ns: exampleAuth,
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | 	},
 | 
					
						
							|  |  |  | 	{
 | 
					
						
							|  |  |  | 		Qname: "wild.d.example.org.", Qtype: dns.TypeTXT,
 | 
					
						
							|  |  |  | 		Answer: []dns.RR{
 | 
					
						
							|  |  |  | 			test.TXT(`alias.example.org. IN	TXT	"Wildcard CNAME expansion"`),
 | 
					
						
							|  |  |  | 			test.CNAME(`wild.d.example.org. IN	CNAME	alias.example.org`),
 | 
					
						
							|  |  |  | 		},
 | 
					
						
							| 
									
										
										
										
											2016-12-07 20:37:29 +00:00
										 |  |  | 		Ns: exampleAuth,
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | 	},
 | 
					
						
							|  |  |  | 	{
 | 
					
						
							|  |  |  | 		Qname: "alias.example.org.", Qtype: dns.TypeTXT,
 | 
					
						
							|  |  |  | 		Answer: []dns.RR{
 | 
					
						
							|  |  |  | 			test.TXT(`alias.example.org. IN	TXT	"Wildcard CNAME expansion"`),
 | 
					
						
							|  |  |  | 		},
 | 
					
						
							| 
									
										
										
										
											2016-12-07 20:37:29 +00:00
										 |  |  | 		Ns: exampleAuth,
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | 	},
 | 
					
						
							|  |  |  | }
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-12-07 20:37:29 +00:00
										 |  |  | var exampleAuth = []dns.RR{
 | 
					
						
							|  |  |  | 	test.NS("example.org.	3600	IN	NS	a.iana-servers.net."),
 | 
					
						
							|  |  |  | 	test.NS("example.org.	3600	IN	NS	b.iana-servers.net."),
 | 
					
						
							|  |  |  | }
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | func TestLookupDoubleWildcard(t *testing.T) {
 | 
					
						
							|  |  |  | 	zone, err := Parse(strings.NewReader(exampleOrg), "example.org.", "stdin")
 | 
					
						
							|  |  |  | 	if err != nil {
 | 
					
						
							| 
									
										
										
										
											2016-11-05 14:39:49 +00:00
										 |  |  | 		t.Fatalf("Expect no error when reading zone, got %q", err)
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | 	}
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	fm := File{Next: test.ErrorHandler(), Zones: Zones{Z: map[string]*Zone{"example.org.": zone}, Names: []string{"example.org."}}}
 | 
					
						
							|  |  |  | 	ctx := context.TODO()
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	for _, tc := range wildcardDoubleTestCases {
 | 
					
						
							|  |  |  | 		m := tc.Msg()
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 		rec := dnsrecorder.New(&test.ResponseWriter{})
 | 
					
						
							|  |  |  | 		_, err := fm.ServeDNS(ctx, rec, m)
 | 
					
						
							|  |  |  | 		if err != nil {
 | 
					
						
							| 
									
										
										
										
											2016-11-05 14:39:49 +00:00
										 |  |  | 			t.Errorf("Expected no error, got %v\n", err)
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | 			return
 | 
					
						
							|  |  |  | 		}
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 		resp := rec.Msg
 | 
					
						
							|  |  |  | 		sort.Sort(test.RRSet(resp.Answer))
 | 
					
						
							|  |  |  | 		sort.Sort(test.RRSet(resp.Ns))
 | 
					
						
							|  |  |  | 		sort.Sort(test.RRSet(resp.Extra))
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 		if !test.Header(t, tc, resp) {
 | 
					
						
							|  |  |  | 			t.Logf("%v\n", resp)
 | 
					
						
							|  |  |  | 			continue
 | 
					
						
							|  |  |  | 		}
 | 
					
						
							|  |  |  | 		if !test.Section(t, tc, test.Answer, resp.Answer) {
 | 
					
						
							|  |  |  | 			t.Logf("%v\n", resp)
 | 
					
						
							|  |  |  | 		}
 | 
					
						
							|  |  |  | 		if !test.Section(t, tc, test.Ns, resp.Ns) {
 | 
					
						
							|  |  |  | 			t.Logf("%v\n", resp)
 | 
					
						
							|  |  |  | 		}
 | 
					
						
							|  |  |  | 		if !test.Section(t, tc, test.Extra, resp.Extra) {
 | 
					
						
							|  |  |  | 			t.Logf("%v\n", resp)
 | 
					
						
							|  |  |  | 		}
 | 
					
						
							|  |  |  | 	}
 | 
					
						
							|  |  |  | }
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-11-05 14:39:49 +00:00
										 |  |  | func TestReplaceWithAsteriskLabel(t *testing.T) {
 | 
					
						
							|  |  |  | 	tests := []struct {
 | 
					
						
							|  |  |  | 		in, out string
 | 
					
						
							|  |  |  | 	}{
 | 
					
						
							|  |  |  | 		{".", ""},
 | 
					
						
							|  |  |  | 		{"miek.nl.", "*.nl."},
 | 
					
						
							|  |  |  | 		{"www.miek.nl.", "*.miek.nl."},
 | 
					
						
							|  |  |  | 	}
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	for _, tc := range tests {
 | 
					
						
							|  |  |  | 		got := replaceWithAsteriskLabel(tc.in)
 | 
					
						
							|  |  |  | 		if got != tc.out {
 | 
					
						
							|  |  |  | 			t.Errorf("Expected to be %s, got %s", tc.out, got)
 | 
					
						
							|  |  |  | 		}
 | 
					
						
							|  |  |  | 	}
 | 
					
						
							|  |  |  | }
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-10-08 15:22:31 +01:00
										 |  |  | const exampleOrg = `; example.org test file
 | 
					
						
							|  |  |  | example.org.		IN	SOA	sns.dns.icann.org. noc.dns.icann.org. 2015082541 7200 3600 1209600 3600
 | 
					
						
							|  |  |  | example.org.		IN	NS	b.iana-servers.net.
 | 
					
						
							|  |  |  | example.org.		IN	NS	a.iana-servers.net.
 | 
					
						
							|  |  |  | example.org.		IN	A	127.0.0.1
 | 
					
						
							|  |  |  | example.org.		IN	A	127.0.0.2
 | 
					
						
							|  |  |  | *.w.example.org.        IN      TXT     "Wildcard"
 | 
					
						
							|  |  |  | a.b.c.w.example.org.    IN      TXT     "Not a wildcard"
 | 
					
						
							|  |  |  | *.c.example.org.        IN      TXT     "c Wildcard"
 | 
					
						
							|  |  |  | *.d.example.org.        IN      CNAME   alias.example.org.
 | 
					
						
							|  |  |  | alias.example.org.      IN      TXT     "Wildcard CNAME expansion"
 | 
					
						
							|  |  |  | `
 |