[dns-operations] DNSSEC and qmail

Tony Finch dot at dotat.at
Thu Oct 8 10:54:13 UTC 2009


We've just had a report of qmail being unable to deliver mail to our site.
The cam.ac.uk zone has been signed for a few months, and it seems that
some of our DNS responses blow out qmail's 512 byte response buffer. Its
error messsage is "CNAME lookup failed temporarily" but in fact qmail
actually performs an T_ANY lookup which produces a 1.3KB reply (DO=0).

Tony.
-- 
f.anthony.n.finch  <dot at dotat.at>  http://dotat.at/
GERMAN BIGHT HUMBER: SOUTHWEST 5 TO 7. MODERATE OR ROUGH. SQUALLY SHOWERS.
MODERATE OR GOOD.



More information about the dns-operations mailing list