dnsmasq That Keeps Private Names Home And Drops Rebinding Answers
dnsmasq from AppStream answering your local names and caching the rest: bound only to the addresses you name, plain names and private reverse lookups kept on the host, upstream answers pointing at private addresses dropped, DNSSEC validated. The live test reads dnsmasq's own upstream counters to prove what was not forwarded. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-08 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-dnsmasq?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [dnsmasq That Keeps Private Names Home And Drops Rebinding Answers](https://www.iac-bazaar.com/catalog/ansible-dnsmasq?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# dnsmasq That Keeps Private Names Home And Drops Rebinding Answers: https://www.iac-bazaar.com/catalog/ansible-dnsmasq (download from your IaC Bazaar account)
```Preview:
Documentation
dnsmasq
dnsmasq from AppStream answering your local names and caching everything else: bound only to the addresses you name, plain names and private reverse lookups kept on the host, upstream answers that point a public name at a private address dropped, and DNSSEC validated. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No download, and no version to pin. EL 10 packages dnsmasq, so the
role installs it by name and takes what the distribution ships: a security
update arrives through dnf, not through a new release of this role. What the
role owns is the configuration and the proof that the service works.
The distribution's unit, our configuration. The role installs dnsmasq,
replaces /etc/dnsmasq.conf (root 0644, checked by dnsmasq --test first; it
still includes /etc/dnsmasq.d/*.conf) and enables the package's
dnsmasq.service, which drops to the dnsmasq user. The listener is
127.0.0.1:53 by default; the live test reads the TCP and UDP sockets and
expects loopback only.
listen-address alone still listens everywhere. Give dnsmasq a
listen-address without bind-interfaces and it opens 0.0.0.0:53 and
[::]:53 and filters in software: a client on another interface timed out
rather than being refused, and nothing else can bind port 53 (measured). The
role always writes bind-interfaces, so the listed addresses are the only
sockets.
What the package sends upstream. By default dnsmasq forwards a plain name
(nas) and a reverse lookup for a private address (10.9.8.7) to the public
resolver, and passes on an upstream answer that points a public name at a
private address - the move a DNS rebinding attack needs. The role sets
domain-needed, bogus-priv and stop-dns-rebind: the live test reads
dnsmasq's own per-server counters (servers.bind) and finds them unchanged
after a plain name, a private reverse lookup and a miss in the local domain,
then changed after a public name; and a test upstream's private answer is
dropped, with "possible DNS-rebind attack detected" in the journal. Answers in
127.0.0.0/8 stay allowed (dnsmasq_rebind_localhost_ok), because DNS
blocklists use them. dnsmasq also treats the documentation ranges as private.
DNSSEC validated by the cache itself. With dnsmasq_dnssec dnsmasq checks
signatures and flags a good answer ad; with it off, the flag is gone (the live
test reads it). A broken signature (dnssec-failed.org) answers SERVFAIL - but
Quad9, the default upstream, returns that by itself too, so with Quad9 that
part is not dnsmasq's doing; it is with an upstream that does not validate.
Every name checked after a start. dnsmasq --test passes a host-record
whose address does not parse, and that name then answers NXDOMAIN (measured).
The role asks for each name in dnsmasq_hosts after every start and fails on
any that does not answer the addresses it wrote.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-unbound-resolver
Unbound on loopback: DNSSEC validated locally against the root anchor, query names minimised, version hidden, and upstream over DNS-over-TLS by default because many networks reset TCP 53 to anything but a known resolver, which breaks full recursion the moment a DNSKEY answer outgrows UDP. Recursion is one setting away. Original role, live-tested on Rocky Linux 10.
ansible-bind-authoritative
BIND as an authoritative-only server. The package is a loopback resolver; add a zone and anyone who can query can copy the whole zone, and version.bind names the 9.18 to attack. This role turns recursion off, refuses transfers to anyone not listed, hides the identity records, rate-limits responses, and renders zones from data checked before they land. Original role, live-tested on Rocky Linux 10.
ansible-coredns
CoreDNS from the upstream release (sha256-verified) as a hardened system service answering authoritatively for your zones on 127.0.0.1:53 as a system user (CAP_NET_BIND_SERVICE through the unit), forwarding only when you name upstreams. The live test digs the example zone's A record with the aa flag, an NXDOMAIN in the zone and a REFUSED outside it. Original role, live-tested on Rocky Linux 10.
ansible-nsd
NSD from EPEL: an authoritative-only server for your zones, the configuration and every zone checked by NSD's own tools first, transfers only to the addresses and TSIG keys you name, response rate limiting, and the state directory the package leaves unwritable fixed. The live test gets the zone with the key and is refused without it. Original role, live-tested on Rocky Linux 10.
ansible-pdns-recursor
PowerDNS Recursor from EPEL on loopback: DNSSEC validated, and every upstream query sent over DNS-over-TLS with each forwarder's certificate checked against the name it must carry. The live test counts every upstream query as TLS, gets SERVFAIL for a broken signature, and has a copy naming the wrong certificate answer nothing. Original role, live-tested on Rocky Linux 10.
ansible-powerdns
PowerDNS authoritative from EPEL with its SQLite backend; the live test adds a zone through the API, gets the record from dig and NXDOMAIN for an unknown name, sees the API refuse a caller with no key, and reads the query counter. The schema is recovered when a docs-stripped host lacks it. Original role, live-tested on Rocky Linux 10.