The remote DNS server answers to any request. It is possible to query
the name servers (NS) of the root zone ('.') and get an answer that
is bigger than the original request. By spoofing the source IP
address, a remote attacker can leverage this 'amplification' to launch
a denial of service attack against a third-party host using the remote
DNS server.