I was the one asking about water.com. I'd started a separate thread hoping not to tromp on the OP of the earlier thread but apparently didn't succeed.
I know the reason for the SOA/MX report so never asked about that. I did ask about the delegation messages but at this point as noted earlier I'm fairly convinced it is a bug in the way they do the test at iis.se rather than an actual issue. (Believe me - I'd HEAR VERY QUICKLY if water.com became inaccessible from the internet.) I was asking the question to see if there was a tweak I needed but based responses I don't think so. -----Original Message----- From: bind-users-bounces+jlightner=water....@lists.isc.org [mailto:bind-users-bounces+jlightner=water....@lists.isc.org] On Behalf Of Kevin Oberman Sent: Wednesday, September 21, 2011 12:30 PM To: Niall O'Reilly Cc: bind-users Subject: Re: Delegation check failed On Wed, Sep 21, 2011 at 2:25 AM, Niall O'Reilly <niall.orei...@ucd.ie> wrote: > > On 21 Sep 2011, at 02:08, Kevin Oberman wrote: > >> dig confirms that .com had the glue for water.com. > > As does dnscheck.iis.se. > Indeed, none of the test history (5 tests, today and yasterday) > archived for water.com at this site shows any delegation problem. > Only a warning is shown against the SOA: > > Failed to connect to smtpbh1.water.com (12.44.84.193). > > I guess that this means that an MX host is protected in some way. > > Is there some other "dnscheck" that people are using, and which > is causing confusion? Matt, Are you running the "Undelegated domain test" or just the default "Domain test"? Only the "Undelegated domain test" is showing the error. It is still reporting it now. Nameserver dswadns1.water.com is listed for zone water.com without address information. Nameserver dswadns2.water.com is listed for zone water.com without address information. The SOA issue is sort of real. The preferred MX for the SOA contact is smtpbh1.water.com and attempts to connect to port 25 on that system time out, as does an attempt to smtpbh2. But smtp.water.com is fine so I don't this this an appropriate report, either. Again, the gtld servers do have the required glue. ; <<>> DiG 9.8.1 <<>> ns +norecurse water.com. @f.gtld-servers.net. ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 55373 ;; flags: qr; QUERY: 1, ANSWER: 0, AUTHORITY: 2, ADDITIONAL: 2 ;; QUESTION SECTION: ;water.com. IN NS ;; AUTHORITY SECTION: water.com. 172800 IN NS dswadns1.water.com. water.com. 172800 IN NS dswadns2.water.com. ;; ADDITIONAL SECTION: dswadns1.water.com. 172800 IN A 12.44.84.213 dswadns2.water.com. 172800 IN A 12.44.84.214 ;; Query time: 39 msec ;; SERVER: 192.35.51.30#53(192.35.51.30) ;; WHEN: Wed Sep 21 09:28:37 2011 ;; MSG SIZE rcvd: 105 Still looks like a bug in dnscheck to me. -- R. Kevin Oberman, Network Engineer - Retired E-mail: kob6...@gmail.com _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users Proud partner. Susan G. Komen for the Cure. Please consider our environment before printing this e-mail or attachments. ---------------------------------- CONFIDENTIALITY NOTICE: This e-mail may contain privileged or confidential information and is for the sole use of the intended recipient(s). If you are not the intended recipient, any disclosure, copying, distribution, or use of the contents of this information is prohibited and may be unlawful. If you have received this electronic transmission in error, please reply immediately to the sender that you have received the message in error, and delete it. Thank you. ---------------------------------- _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users