[191265] in North American Network Operators' Group
Re: Cloudflare reverse DNS SERVFAIL, normal?
daemon@ATHENA.MIT.EDU (Niels Bakker)
Wed Aug 31 10:18:33 2016
X-Original-To: nanog@nanog.org
Date: Wed, 31 Aug 2016 16:18:27 +0200
From: Niels Bakker <niels=nanog@bakker.net>
To: nanog@nanog.org
Mail-Followup-To: nanog@nanog.org
In-Reply-To: <2171203D-A70B-415D-B0A5-192591DF0575@delong.com>
Errors-To: nanog-bounces@nanog.org
* owen@delong.com (Owen DeLong) [Wed 31 Aug 2016, 01:47 CEST]:
>You don’t get NXDOMAIN when a nameserver gets a request for a zone
>it doesn’t serve.
Correct in most cases (there's an edge case where a server is [mis]
configured as authoritative with its own empty . and its regular
zones and allows global querying; it's similar to asking a root
server for anything in a nonexistent TLD).
>You either get SERVFAIL or you get NS records back as a referral.
Or REFUSED.
-- Niels.