[dns-operations] [Solved] (not just) Quad9 denial of existence for _25._tcp.mx1.p01.antagonist.nl IN TLSA

Viktor Dukhovni ietf-dane at dukhovni.org
Thu Nov 28 02:55:25 UTC 2019


Root cause found, the antagonist.nl domain has 3 listed nameservers:

    ns1.antagonist.nl.
    ns2.antagonist.net.
    ns3.antagonist.de.

but the IP address returned by the actual antagonist.de zone:

    ns3.antagonist.de. IN A 139.162.173.192

differs from the glue record returned from the .DE zone:

    ns3.antagonist.de. IN A 66.228.42.134

And it is this 66.228.42.134 (returned in the .DE glue) nameserver that is
serving freshly signed denial of existence for _tcp.mx1.p01.antagonist.nl.

-- 
    Viktor.



More information about the dns-operations mailing list