Exactly why is this affecting non-spamhaus services? Is it just shared dns servers or actual IP traffic being throttled ?
back
3 comments
According to the article(s) the DDoS is so big that it is not just clogging up spamhaus' links as it is intended to but also the backbone leading up to said links. That would affect everyone and not just spamhaus.
Also, the DNS servers are being used to perform the attack via DNS amplification, the slowdown is not caused by clogged DNS servers.
I don't have the exact quote but one of the articles likens the situation to having a motorway with on-ramps and off-ramps to individual networks/hosts. The usual DDoS seeks to clog the on-ramp or off-ramp the target uses by sending too many cars their way. However, this attack is so big that it's clogging up the motorway itself not just on/off-ramps.
CloudFlare, Google, and others are lending their infrastructure to absorb the attack and increase reliability of Spamhaus blacklist propagation.
A lot of spam filters rely on spamhaus.
This is true. However the reason this affects non-Spamhaus servers is because there is so much traffic that it is literally clogging the backbone.