Tony Finch dot at dotat.at
Fri Jun 1 11:07:50 UTC 2018

Con Wieland <cwieland at uci.edu> wrote:

> I have a nameserver that can not resolve extranet.aro.army.mil.

The end of the CNAME chain is e1008.d.akamaiedge.akamai.csd.disa.mil. The
authoritative servers for this name really like to drop queries if they
don't like the qtype. This is very bad, because it makes it easy to upset

My server can usually resolve this name OK, but I can kick it into
SERVFAIL mode with:

	while [ -n "$d" ];
	do	dig $d in ns $d in ds $d in dnskey;
		d=$(echo $d | sed 's/^[^.]*[.]//');

serve-stale helps my resolver recover from being kicked like this.

