Why does an NS query for this domain only return one NS record?CNAME to another domain fails on some office...

ESPP--any reason not to go all in?

How to write a chaotic neutral protagonist and prevent my readers from thinking they are evil?

If nine coins are tossed, what is the probability that the number of heads is even?

The past tense for the quoting particle って

Does the in-code argument passing conventions used on PDP-11's have a name?

Is this nominative case or accusative case?

Is divide-by-zero a security vulnerability?

Why can't we use freedom of speech and expression to incite people to rebel against government in India?

What is the purpose of a disclaimer like "this is not legal advice"?

DC input on op amp integrator

What is "desert glass" and what does it do to the PCs?

Why would the IRS ask for birth certificates or even audit a small tax return?

The need of reserving one's ability in job interviews

Should we avoid writing fiction about historical events without extensive research?

School performs periodic password audits. Is my password compromised?

3.5% Interest Student Loan or use all of my savings on Tuition?

Create chunks from an array

I've given my players a lot of magic items. Is it reasonable for me to give them harder encounters?

Should I use HTTPS on a domain that will only be used for redirection?

An Undercover Army

Who is at the mall?

Dukha vs legitimate need

Align equations with text before one of them

Is every open circuit a capacitor?



Why does an NS query for this domain only return one NS record?


CNAME to another domain fails on some office networks, why?Registering a co.za using private nameserversDNS setup with BINDGlobal Reverse DNS look-ups not workingHow to correctly configure nameserversWindows 2008 dns server can't find his own host nameHow to determine where an IP returned by NSLOOKUP is coming fromUbuntu uses external DNS to resolve localhostdns lookup at different dns serversDNS server with bind in Debian 9













0















I'm trying to figure out why an NS query for a domain only returns one NS record rather than both the NS records set via the registrar. I don't have access to the DNS server. If I query the roots, the response is as expected:



.dig.exe NS example.com "@c.gtld-servers.net"

; <<>> DiG 9.12.3-P1 <<>> NS example.com @c.gtld-servers.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 36123
;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 2, ADDITIONAL: 3
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;example.com. IN NS

;; AUTHORITY SECTION:
example.com. 172800 IN NS ns1.example.net.
example.com. 172800 IN NS ns2.example.net.

;; ADDITIONAL SECTION:
ns1.example.net. 172800 IN A 192.0.2.1
ns2.example.net. 172800 IN A 192.0.2.2

;; Query time: 62 msec
;; SERVER: 192.26.92.30#53(192.26.92.30)
;; WHEN: Thu Mar 07 17:08:18 Canada Central Standard Time 2019
;; MSG SIZE rcvd: 133


However, if I directly query the authoritative server for the domain, it only gives me one record:



.dig.exe NS example.com "@ns1.example.net"

; <<>> DiG 9.12.3-P1 <<>> NS example.com @ns1.example.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 49473
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;example.com. IN NS

;; ANSWER SECTION:
example.com. 1800 IN NS ns1.example.net.

;; ADDITIONAL SECTION:
ns1.example.net. 1800 IN A 192.0.2.1

;; Query time: 78 msec
;; SERVER: 192.0.2.1#53(192.0.2.1)
;; WHEN: Thu Mar 07 17:20:22 Canada Central Standard Time 2019
;; MSG SIZE rcvd: 88


The secondary NS exists:



.dig.exe NS example.com "@ns2.example.net"

; <<>> DiG 9.12.3-P1 <<>> NS example.com @ns2.example.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60334
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;example.com. IN NS

;; ANSWER SECTION:
example.com. 1800 IN NS ns1.example.net.

;; ADDITIONAL SECTION:
ns1.example.net. 1800 IN A 192.0.2.1

;; Query time: 62 msec
;; SERVER: 192.0.2.2#53(192.0.2.2)
;; WHEN: Thu Mar 07 17:29:07 Canada Central Standard Time 2019
;; MSG SIZE rcvd: 88


I have 2 questions:




  1. What's configured wrong? I'm assuming it's the zone file for the domain, but I've never run a DNS server.

  2. What impact will the improper config have?









share























  • Looks like the DNS servers are misconfigured. If you don't run them, you need to be complaining to whoever does.

    – Michael Hampton
    5 mins ago


















0















I'm trying to figure out why an NS query for a domain only returns one NS record rather than both the NS records set via the registrar. I don't have access to the DNS server. If I query the roots, the response is as expected:



.dig.exe NS example.com "@c.gtld-servers.net"

; <<>> DiG 9.12.3-P1 <<>> NS example.com @c.gtld-servers.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 36123
;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 2, ADDITIONAL: 3
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;example.com. IN NS

;; AUTHORITY SECTION:
example.com. 172800 IN NS ns1.example.net.
example.com. 172800 IN NS ns2.example.net.

;; ADDITIONAL SECTION:
ns1.example.net. 172800 IN A 192.0.2.1
ns2.example.net. 172800 IN A 192.0.2.2

;; Query time: 62 msec
;; SERVER: 192.26.92.30#53(192.26.92.30)
;; WHEN: Thu Mar 07 17:08:18 Canada Central Standard Time 2019
;; MSG SIZE rcvd: 133


However, if I directly query the authoritative server for the domain, it only gives me one record:



.dig.exe NS example.com "@ns1.example.net"

; <<>> DiG 9.12.3-P1 <<>> NS example.com @ns1.example.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 49473
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;example.com. IN NS

;; ANSWER SECTION:
example.com. 1800 IN NS ns1.example.net.

;; ADDITIONAL SECTION:
ns1.example.net. 1800 IN A 192.0.2.1

;; Query time: 78 msec
;; SERVER: 192.0.2.1#53(192.0.2.1)
;; WHEN: Thu Mar 07 17:20:22 Canada Central Standard Time 2019
;; MSG SIZE rcvd: 88


The secondary NS exists:



.dig.exe NS example.com "@ns2.example.net"

; <<>> DiG 9.12.3-P1 <<>> NS example.com @ns2.example.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60334
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;example.com. IN NS

;; ANSWER SECTION:
example.com. 1800 IN NS ns1.example.net.

;; ADDITIONAL SECTION:
ns1.example.net. 1800 IN A 192.0.2.1

;; Query time: 62 msec
;; SERVER: 192.0.2.2#53(192.0.2.2)
;; WHEN: Thu Mar 07 17:29:07 Canada Central Standard Time 2019
;; MSG SIZE rcvd: 88


I have 2 questions:




  1. What's configured wrong? I'm assuming it's the zone file for the domain, but I've never run a DNS server.

  2. What impact will the improper config have?









share























  • Looks like the DNS servers are misconfigured. If you don't run them, you need to be complaining to whoever does.

    – Michael Hampton
    5 mins ago
















0












0








0








I'm trying to figure out why an NS query for a domain only returns one NS record rather than both the NS records set via the registrar. I don't have access to the DNS server. If I query the roots, the response is as expected:



.dig.exe NS example.com "@c.gtld-servers.net"

; <<>> DiG 9.12.3-P1 <<>> NS example.com @c.gtld-servers.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 36123
;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 2, ADDITIONAL: 3
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;example.com. IN NS

;; AUTHORITY SECTION:
example.com. 172800 IN NS ns1.example.net.
example.com. 172800 IN NS ns2.example.net.

;; ADDITIONAL SECTION:
ns1.example.net. 172800 IN A 192.0.2.1
ns2.example.net. 172800 IN A 192.0.2.2

;; Query time: 62 msec
;; SERVER: 192.26.92.30#53(192.26.92.30)
;; WHEN: Thu Mar 07 17:08:18 Canada Central Standard Time 2019
;; MSG SIZE rcvd: 133


However, if I directly query the authoritative server for the domain, it only gives me one record:



.dig.exe NS example.com "@ns1.example.net"

; <<>> DiG 9.12.3-P1 <<>> NS example.com @ns1.example.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 49473
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;example.com. IN NS

;; ANSWER SECTION:
example.com. 1800 IN NS ns1.example.net.

;; ADDITIONAL SECTION:
ns1.example.net. 1800 IN A 192.0.2.1

;; Query time: 78 msec
;; SERVER: 192.0.2.1#53(192.0.2.1)
;; WHEN: Thu Mar 07 17:20:22 Canada Central Standard Time 2019
;; MSG SIZE rcvd: 88


The secondary NS exists:



.dig.exe NS example.com "@ns2.example.net"

; <<>> DiG 9.12.3-P1 <<>> NS example.com @ns2.example.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60334
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;example.com. IN NS

;; ANSWER SECTION:
example.com. 1800 IN NS ns1.example.net.

;; ADDITIONAL SECTION:
ns1.example.net. 1800 IN A 192.0.2.1

;; Query time: 62 msec
;; SERVER: 192.0.2.2#53(192.0.2.2)
;; WHEN: Thu Mar 07 17:29:07 Canada Central Standard Time 2019
;; MSG SIZE rcvd: 88


I have 2 questions:




  1. What's configured wrong? I'm assuming it's the zone file for the domain, but I've never run a DNS server.

  2. What impact will the improper config have?









share














I'm trying to figure out why an NS query for a domain only returns one NS record rather than both the NS records set via the registrar. I don't have access to the DNS server. If I query the roots, the response is as expected:



.dig.exe NS example.com "@c.gtld-servers.net"

; <<>> DiG 9.12.3-P1 <<>> NS example.com @c.gtld-servers.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 36123
;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 2, ADDITIONAL: 3
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;example.com. IN NS

;; AUTHORITY SECTION:
example.com. 172800 IN NS ns1.example.net.
example.com. 172800 IN NS ns2.example.net.

;; ADDITIONAL SECTION:
ns1.example.net. 172800 IN A 192.0.2.1
ns2.example.net. 172800 IN A 192.0.2.2

;; Query time: 62 msec
;; SERVER: 192.26.92.30#53(192.26.92.30)
;; WHEN: Thu Mar 07 17:08:18 Canada Central Standard Time 2019
;; MSG SIZE rcvd: 133


However, if I directly query the authoritative server for the domain, it only gives me one record:



.dig.exe NS example.com "@ns1.example.net"

; <<>> DiG 9.12.3-P1 <<>> NS example.com @ns1.example.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 49473
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;example.com. IN NS

;; ANSWER SECTION:
example.com. 1800 IN NS ns1.example.net.

;; ADDITIONAL SECTION:
ns1.example.net. 1800 IN A 192.0.2.1

;; Query time: 78 msec
;; SERVER: 192.0.2.1#53(192.0.2.1)
;; WHEN: Thu Mar 07 17:20:22 Canada Central Standard Time 2019
;; MSG SIZE rcvd: 88


The secondary NS exists:



.dig.exe NS example.com "@ns2.example.net"

; <<>> DiG 9.12.3-P1 <<>> NS example.com @ns2.example.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60334
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;example.com. IN NS

;; ANSWER SECTION:
example.com. 1800 IN NS ns1.example.net.

;; ADDITIONAL SECTION:
ns1.example.net. 1800 IN A 192.0.2.1

;; Query time: 62 msec
;; SERVER: 192.0.2.2#53(192.0.2.2)
;; WHEN: Thu Mar 07 17:29:07 Canada Central Standard Time 2019
;; MSG SIZE rcvd: 88


I have 2 questions:




  1. What's configured wrong? I'm assuming it's the zone file for the domain, but I've never run a DNS server.

  2. What impact will the improper config have?







domain-name-system dns-zone





share












share










share



share










asked 8 mins ago









Ryan JRyan J

1887




1887













  • Looks like the DNS servers are misconfigured. If you don't run them, you need to be complaining to whoever does.

    – Michael Hampton
    5 mins ago





















  • Looks like the DNS servers are misconfigured. If you don't run them, you need to be complaining to whoever does.

    – Michael Hampton
    5 mins ago



















Looks like the DNS servers are misconfigured. If you don't run them, you need to be complaining to whoever does.

– Michael Hampton
5 mins ago







Looks like the DNS servers are misconfigured. If you don't run them, you need to be complaining to whoever does.

– Michael Hampton
5 mins ago












0






active

oldest

votes











Your Answer








StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "2"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f957282%2fwhy-does-an-ns-query-for-this-domain-only-return-one-ns-record%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes
















draft saved

draft discarded




















































Thanks for contributing an answer to Server Fault!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f957282%2fwhy-does-an-ns-query-for-this-domain-only-return-one-ns-record%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

117736 Шеррод Примітки | Див. також | Посилання | Навігаційне...

As a Security Precaution, the user account has been locked The Next CEO of Stack OverflowMS...

Маріан Котлеба Зміст Життєпис | Політичні погляди |...