On Tue, Feb 28, 2017 at 07:13:33PM -0500, Viktor Dukhovni wrote: > > > On Feb 28, 2017, at 7:05 PM, Voytek <li...@sbt.net.au> wrote: > > > > dig -t MX surfacetreatment.be > > > > ; <<>> DiG 9.8.2rc1-RedHat-9.8.2-0.47.rc1.el6_8.4 <<>> -t MX > > surfacetreatment.be > > ;; global options: +cmd > > ;; Got answer: > > ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 25122 ^^^^^^^^ > The problem may be on your end. The report from dnsviz.net also shows > no problems (ignore the errors for a non-responding root namerver): > > http://dnsviz.net/d/surfacetreatment.be/dnssec/
When I look, I see problems in dnsviz regarding DNSSEC. The root key is in the middle of a roll, and I wonder whether there might be a problem resulting from that. If the resolver is validating and can't prove the insecure delegation, it might return SERVFAIL. (But I agree I can see the records there.) The SERVFAIL could also be a broken recursive or a cache failure of some kind. A -- Andrew Sullivan a...@anvilwalrusden.com