<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<div class="moz-cite-prefix"><code>Try these four<br>
</code></div>
<div class="moz-cite-prefix"><code><br>
</code></div>
<div class="moz-cite-prefix"><code>fail01.dnssec.works</code></div>
<div class="moz-cite-prefix"><code>fail02.dnssec.works</code><br>
</div>
<div class="moz-cite-prefix">
<code>fail03.dnssec.works</code></div>
<div class="moz-cite-prefix"><code>fail04.dnssec.works</code></div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">and then with +cd and note the
difference;<br>
</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">On 28.04.2024 08:17, Walter H. via
bind-users wrote:<br>
</div>
<blockquote type="cite"
cite="mid:2bbda85f-6f24-0173-683f-150b29e14d43@mathemainzel.info">On
27.04.2024 16:54, Lee wrote:
<br>
<blockquote type="cite">On Sat, Apr 27, 2024 at 9:50 AM Walter H.
via bind-users
<br>
<a class="moz-txt-link-rfc2396E" href="mailto:bind-users@lists.isc.org"><bind-users@lists.isc.org></a> wrote:
<br>
<blockquote type="cite"># host dnssec-analyzer.verisignlabs.com
<br>
dnssec-analyzer.verisignlabs.com is an alias for
<br>
dnssec-analyzer-gslb.verisignlabs.com.
<br>
dnssec-analyzer-gslb.verisignlabs.com has address
209.131.158.42
<br>
<br>
</blockquote>
Right, the IPv4 address lookup works. Now try looking up the
IPv6 address.
<br>
</blockquote>
<br>
if there was one it would be presented there
<br>
<br>
see here for full answer
<br>
<br>
# host one.one.one.one
<br>
one.one.one.one has address 1.1.1.1
<br>
one.one.one.one has address 1.0.0.1
<br>
one.one.one.one has IPv6 address 2606:4700:4700::1001
<br>
one.one.one.one has IPv6 address 2606:4700:4700::1111
<br>
<br>
<blockquote type="cite">
<br>
I get a status: SERVFAIL instead of a status: NOERROR
<br>
<br>
$ dig dnssec-analyzer.verisignlabs.com aaaa
<br>
<br>
; <<>> DiG 9.16.48-Debian <<>>
dnssec-analyzer.verisignlabs.com aaaa
<br>
;; global options: +cmd
<br>
;; Got answer:
<br>
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id:
60491
<br>
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0,
ADDITIONAL: 1
<br>
<br>
Lee
<br>
</blockquote>
<br>
this can't be a matter of DNSSEC, as there are only signed whole
zones and not just single DNS-records ...
<br>
<br>
would it be a problem with just this DNS zone, why are only
problems getting the IPv6?
<br>
<br>
<br>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
</blockquote>
<p><br>
</p>
</body>
</html>