Authoritative internal server - how do I get rid of...

Elmar K. Bins elmi at
Tue May 21 08:57:32 UTC 2013

... these annoying root lookups:
error (host unreachable) resolving './DNSKEY/IN':
error (host unreachable) resolving './NS/IN':

Hi guys,

I guess a few of you have seen and mitigated this before. We're running
a few BIND server strictly internally - for master zone loading, actually.

Those servers have no external connectivity. Since they seem to routinely
look up stuff concerning ".", I get a lot of the above error messages due
to - certainly - unreachability of anything outside local.

Is there any way I can get those BIND9 servers to *not* look up root stuff?

Recursion is off, and the root hints file has been removed from the local
zone config. No effect.

Any pointers would be much appreciated.


More information about the bind-users mailing list