The domain was always resolvable from a cold cache because the
delegation was always* correct.


The outage happened when the authoritative NS records were changed to
*completely different* names that do not exist.

A totally parent-centric resolver would never have noticed anything wrong.

The "bug" in Unbound is that, in this precise error situation, it
apparently returns SERVFAIL before trying to fall back on the
parent-side NS records.

* As a separate issue, half of the nameservers have out-of-date glue
records with IPs that don't respond.
Matt Nordhoff

