We have a winner! I disabled RPZ on a test DNS server and the problem went away. We do not have a whitelist zone so the issue must be with RPZ zones in general (or the format of the RPZ zone file). _________________________________________________________ Nicholas Miller, OIT, University of Colorado at Boulder
On Sep 10, 2013, at 10:12 AM, Colin Turnbull <[email protected]> wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Are you using RPZ and a whitelist zone? If so, you may see that > behavior from whitelisted records. > > - -Colin _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list [email protected] https://lists.isc.org/mailman/listinfo/bind-users

