Domain is NOT resolving with Google DNS servers 8.8.8.8, 8.8.4.4

0

We recently moved a domain(trontv.com) from Godaddy to Route53,
and Name resolving is very wonky.

Domain is NOT resolving with Google DNS servers 8.8.8.8, 8.8.4.4 (also 1.1.1.1)
Bit It's working well with other DNS servers example: 4.2.2.2

It could NOT be due to DNSSEC. Can someone disable DNSSEC for trontv.com

Thanks

neteng
已提問 5 年前檢視次數 2205 次
4 個答案
0

Hi neteng!

I ran a dig command on your domain trontv.com at 8.8.8.8, 8.8.4.4, 9.9.9.9, and 1.1.1.1 and it had resolved successful. I also tried with my EC2 instance's internal DNS and was successful also.

It seems like I am reading your post about 24 hours after you posted it, so I think the DNS records may have propagated by now. Note that caching DNS resolvers are outside the control of the Amazon Route 53 service and will cache your resource record sets according to their time to live (TTL)

-Michael

AWS
已回答 5 年前
0

Yep , It was actually DNSSEC issue.
issue has been resolved by removing DNSSEC on Godaddy side.

Thanks

neteng
已回答 5 年前
0

Issue due to DNSSEC on Godaddy side.

and It just got resolved by removing it from Godaddy control panel.

Thanks

neteng
已回答 5 年前
0

Hello neteng,

I would like to let you know that at this time, Amazon Route 53 supports DNSSEC only for domain registration but does not support DNSSEC for DNS service:
https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/domain-configure-dnssec.html

Google Public DNS performs DNSSEC validation for all DNS queries by default. So, when a name server fails DNSSEC validation, it returns SERVFAIL/NXDOMAIN.

As you had DNSSEC enabled for your domain and since DNSSEC is disabled with the DNS service (Route 53), the Google Public DNS resolver was returning SERVFAIL error to clients.
Therefore, the issue got resolved when you disabled DNSSEC for your domain on your Registrar i.e. GoDaddy.

Edited by: Charu-aws on Jun 10, 2019 12:08 AM

AWS
支援工程師
已回答 5 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南