Re: General DNS / SPF question

2023-01-07 Thread G.W. Haywood via bind-users
Hi there, On Sat, 7 Jan 2023, Michael Muller wrote: This is my first time posting here, and I'm not sure if it's the right place or not to ask my question. This is a general DNS question, specifically, I think, SPF. Probably not really the right place but the SPF users' list has been a bit de

Re: General DNS / SPF question

2023-01-07 Thread Mark Andrews
Please don’t hijack an existing thread by replying to an existing message for a unrelated subject. It is bad form. Just create a new message and send it to bind-us...@isc.org. -- Mark Andrews > On 8 Jan 2023, at 09:07, Michael Muller via bind-users > wrote: > >  > Hello everyone, > > Thi

General DNS / SPF question

2023-01-07 Thread Michael Muller via bind-users
Hello everyone, This is my first time posting here, and I'm not sure if it's the right place or not to ask my question. This is a general DNS question, specifically, I think, SPF. (Btw, I do use Bind in my system, so that's why I'm here.) I host email using SmarterMail, and all 400+ customer

Re: parental-agent, emtpy DS response ?

2023-01-07 Thread Anders Löwinger
On 2023-01-07 22:22, Mark Andrews wrote: I suspect the problem is that the request does not have RD=1 and you are talking to recursive servers. I changed parental-agents to one of the .SE DNS servers. Jan 07 22:26:48 dns-signer2 named[3428351]: keymgr: checkds DS for key lowinger.se/ECDSAP38

Re: parental-agent, emtpy DS response ?

2023-01-07 Thread Mark Andrews
I suspect the problem is that the request does not have RD=1 and you are talking to recursive servers. The following should work except where the authoritative server does not implement DNS properly and rejects recursive queries rather than just treating the request as not recursive. diff --gi

parental-agent, emtpy DS response ?

2023-01-07 Thread Anders Löwinger
Hi I have some trouble with the parental-agents. Anyone seen this before/can give me a clue to get this working? Tried with my two recursive resolvers first, then localhost. No difference. From the log named[3420650]: zone lowinger.se/IN (signed): checkds: empty DS response from 2a00:f680:1