cname.dnsp.co
The control case for the mismatch test.
What it does
Here the message is carried in the target of an alias. Unlike a mismatched type, every resolver follows an alias, so this should survive any path. It isolates whether mismatch filtering was really the cause of what you saw.
Example
$ dig cname.dnsp.co CNAME +short
this-text-rides-in-a-name.dnsp.co.
Reading the answer
the alias and its payload
The path passes ordinary records through untouched.
nothing
Something is rewriting heavily, well beyond type filtering.
Notes
- Run mismatch.dnsp.co first. This test only means something as a comparison.