Re: DNSSEC troubleshooting on a recursive server.

2013-08-07 Thread Mark Andrews
> > In any event, as Mark has suggested, you don't want to dig the RRSIG > > yourself. Rather, use: > > > > dig +dnssec zygo.com a > > > > ...and if you get a SERVFAIL: > > > > dig +dnssec +cd zygo.com a > dig +dnssec +cd zygo.com a resolved the domain. "RESOLVED THE DOMAIN" is not !@#$#!$!@#!$@#

Re: Suggestions for primary DNS hosting

2013-08-07 Thread Chip Marshall
Up front, I work for Dyn, but I'm not posting in any official capacity, just here to help. On our consumer service, Dyn Standard DNS, you might run into issues with some DNS record types, though SPF and TXT are definitely supported. If you doing anything sufficiently weird, you might want to run y

Re: DNSSEC troubleshooting on a recursive server.

2013-08-07 Thread Grant Keller
On 08/07/2013 01:53 AM, Phil Mayers wrote: > On 08/07/2013 12:09 AM, Grant Keller wrote: >> Hello, >> >> We have 7 recursive DNS servers running Bind 9.9.2, and we are seeing >> some strange behavoir validating DNSSEC. We have seen this happen a few >> times, and in the past the problem has gone aw

Re: Suggestions for primary DNS hosting

2013-08-07 Thread Mike Hale
I think DynDNS meets all your requirements. They had pretty good service and a solid infrastructure. At a certain point, you pay based on the queries per second, which is the only reason we migrated our DNS in-house. It's otherwise pretty cheap for what you get. On Wed, Aug 7, 2013 at 6:13 AM,

Suggestions for primary DNS hosting

2013-08-07 Thread Matthew Huff
Within the last few years, we have drastically reduced our DNS footprint, as well as our datacenter size. We are looking to migrate our primary DNS to a provider, but I'm having trouble finding ones that meet our requirements 1) Provide primary DNS without necessary being the registar for the do

Re: DNSSEC troubleshooting on a recursive server.

2013-08-07 Thread Phil Mayers
On 08/07/2013 12:09 AM, Grant Keller wrote: Hello, We have 7 recursive DNS servers running Bind 9.9.2, and we are seeing some strange behavoir validating DNSSEC. We have seen this happen a few times, and in the past the problem has gone away when the server is rebooted, so my first guess is that