Dealing with "unexpected RCODE (SERVFAIL)"

Matus UHLAR - fantomas uhlar at fantomas.sk
Tue Mar 16 13:15:39 UTC 2010


> > On 16.03.10 09:45, Ruben Laban wrote:
> > > In my logs I see numerous line like these:
> > > 
> > > Mar 16 04:59:13 mx02 named[4606]: unexpected RCODE (SERVFAIL) 
> > > resolving 'hotmeil.com/MX/IN': 10.2.1.3#53
> > > Mar 16 04:59:14 mx02 named[4606]: unexpected RCODE (SERVFAIL) 
> > > resolving 'hotmeil.com/MX/IN': 10.0.1.3#53
> > > Mar 16 04:59:15 mx02 named[4606]: unexpected RCODE (SERVFAIL) 
> > > resolving 'hotmeil.com/MX/IN': 10.1.1.3#53

> In message <20100316090709.GC7223 at fantomas.sk>, Matus UHLAR - fantomas writes:
> > the microsoft's nameservers are providing only A and TXT records for
> > hotmeil.com. They return ". IN SOA (NOERROR)" for other questions.
> > This is apparently invalid and causes the SERVFAIL.
> > 
> > seems it's time to blame microsoft.

On 16.03.10 23:43, Mark Andrews wrote:
> And the lack of a way to register a name in COM without creating a
> delegation.  And the lack of a way to say this domain name is not
> a valid email domain.

It's apparently because DNS was designed to provide records that exist, not
those that do not.

> The best thing would be for hotmeil.com to always return NXDOMAIN
> and people would correct their spelling errors.  Unfortunately there
> is not way to register hotmeil.com without creating a delegation
> and you could you have these ISP's that hijack NXDOMAIN and rewrite
> it so you get a A record instead of NXDOMAIN.

> So Microsoft have to supply a A record but they don't want it to
> be used for email so they need to break the MX lookup so MTA's soft
> fail and eventually (days later) return the email to the sender.

You can also register a domain and not provide any records for it (except
SOA and NS), which would be best in current situation imho.

However Microsoft decided to provide A records for hotmeil.com (and
www.hotmeil.com too), so they don't want people to fix their typos, but are
doing it themselves instead.

Yes, there could be way to define a domain that has A record but does not
provide mail service. Unluckily, in case of MX nonexistance the A is used
(as implicit zero-priority MX).

-- 
Matus UHLAR - fantomas, uhlar at fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
"Two words: Windows survives." - Craig Mundie, Microsoft senior strategist
"So does syphillis. Good thing we have penicillin." - Matthew Alton



More information about the bind-users mailing list