On 17 Apr 2019, at 16:00, Alexander Dupuy wrote:

> On a more practical note, in a previous case where an authority was
> returning "bald-faced lies" (proving the nonexistence of anything but the
> zone apex in a non-empty zone, in contrast to the minimal white and black
> lies) we had to disable aggressive NSEC cache synthesis as it was causing
> spurious negative answers. The domain was later identified as using
> PowerDNS, and the solution was for them to run pdnsutil rectify-zone to
> rebuild the NSEC chain (
> https://community.cloudflare.com/t/leg-br-domains-failing-to-query-1-1-1-1/18379/2).
> It is possible that this is all that epik.com needs to do to fix this issue.

Yes, this seems likely - the ‘bald-faced lies’ are one smoking gun, and the RRSIG timestamps (Thursday midnight, a few weeks apart) are another dead giveaway for PowerDNS.

epik.com.		300	IN	RRSIG	A 13 2 300 20190425000000 20190404000000 5305 epik.com. cZGaZvBRn/8ggkCMTTWMyQHIhkFytmKHwa4U0pBCsI1tUVIqgtkENsWF I2rJATLN2Du+989q0sDJGpVseZPKsw==

