On 9/18/2012 9:45 AM, M. Meadows wrote:

dig www.careerone.com.au +short @8.8.8.8
www.careerone.com.au.edgesuite.net.
a903.g.akamai.net.
208.44.23.99
208.44.23.121

Why does the above dig work when

dig careerone.com.au +nssearch @8.8.8.8
SOA dns0.news.com.au. hostmaster.news.com.au. 2012082200 3600 1200 86400 1200 from server usw1.akam.net in 106 ms. SOA dns0.news.com.au. hostmaster.news.com.au. 2012082200 3600 1200 86400 1200 from server usw4.akam.net in 136 ms. SOA dns0.news.com.au. hostmaster.news.com.au. 2012082200 3600 1200 86400 1200 from server usc4.akam.net in 124 ms. SOA dns0.news.com.au. hostmaster.news.com.au. 2012082200 3600 1200 86400 1200 from server usc1.akam.net in 40 ms. SOA dns0.news.com.au. hostmaster.news.com.au. 2012082200 3600 1200 86400 1200 from server usw5.akam.net in 190 ms. SOA dns0.news.com.au. hostmaster.news.com.au. 2012082200 3600 1200 86400 1200 from server ns1-24.akam.net in 171 ms. SOA dns0.news.com.au. hostmaster.news.com.au. 2012082200 3600 1200 86400 1200 from server asia1.akam.net in 161 ms. SOA dns0.news.com.au. hostmaster.news.com.au. 2012082200 3600 1200 86400 1200 from server ns1-50.akam.net in 161 ms.

shows 8 auth nameservers for careerone.com.au

and if you use

dig www.careerone.com.au +short @<any of the 8 auth nameservers>

you get no answer.

How does that work? Where does the 8.8.8.8 google public dns server get its answer from?

www.careerone.com.au is an alias (through chained aliasing) ultimately to a903.g.akamai.net. To get an authoritative answer for a903g.akamai.net you'd need to ask one of the g.akamai.net nameservers. Which is presumably what Google's public resolver did to get the answers it returned to your query.

            - Kevin
_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to