[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[public-dns-discuss] Re: DNSSEC error thrown by 8.8.8.8 and 1.1.1.1 servers, works fine with others



There seem to have been some issues retrieving DNSSEC-signed records from .COM name servers using IPv6: http://dnsviz.net/d/bugfender.com/WyH_dw/dnssec/. The lack of UDP responses is likely due to IPv6 fragmentation for responses with DNS message size more than 1252 and less than default EDNS bufsize 4096. This could have led to failed DS key lookups for this signed domain when IPv6 was used.

A more recent DNSViz check (http://dnsviz.net/d/bugfender.com/WyK1qg/dnssec/) isn't showing this problem any more, so it is likely to go away as the DS record for your domain is successfully retrieved.

--
--
========================================================
You received this message because you are subscribed to the Google
Groups "public-dns-discuss" group.
To post to this group, send email to public-dns-discuss AT googlegroups.com
To unsubscribe from this group, send email to
public-dns-discuss+unsubscribe AT googlegroups.com
For more options, visit this group at
http://groups.google.com/group/public-dns-discuss
For more information on Google Public DNS, please visit
http://developers.google.com/speed/public-dns
========================================================
---
You received this message because you are subscribed to the Google Groups "public-dns-discuss" group.
To unsubscribe from this group and stop receiving emails from it, send an email to public-dns-discuss+unsubscribe AT googlegroups.com.
For more options, visit https://groups.google.com/d/optout.