Elektrine lite

← Feed

@grahamadams@toot.wales

Post #1225024

2026-04-05 07:35 UTC

@kasperd @jamesthomson @revk Perhaps it was falling back to TCP and DNS over TCP was blocked by the network? I have come across this before.

Replies (1)

  • @kasperd@westergaard.social 2026-04-05 11:19

    I don’t recall if it attempted falling back to TCP. There was no blocking on the network where the DNS recursor was hosted. But many authoritative DNS servers lack TCP support. In any case it also failed resolution with authoritative servers that did support TCP. What I do recall observing was that the BIND 9 recursor would try all of the different authoritative DNS servers one after each other. It would simply ignore every DNS response if it had taken more than one second to arrive. Even after having received and ignored perfectly valid DNS responses it would keep sending more DNS requests over UDP to other authoritative servers for the domain.

    Open ##1225025