Wandering Thoughts archives

2006-08-21

How not to set up your DNS (part 10)

This one is a close variation of HowNotToDoDNSIX, but it earns extra points for making the reverse error from a common one. Presented in semi-illustrated format:

; dig +short ns system-bank.net.
dns01.system-bank.net.
dns02.system-bank.net.

(At this point I will pause to note that dns01.system-bank.net and dns02.system-bank.net have the same IP address, 218.227.163.13, a trick that was featured back at the start of this series.)

; dig a server.system-bank.net. @218.227.163.13
[...]
;; AUTHORITY SECTION:
system-bank.net. IN NS dns01.
system-bank.net. IN NS dns02.

(TTLs have been omitted for clarity.)

The usual error is for people to leave out the trailing dot on things like NS records pointing to external machines, so that you get an NS record of 'ns1.other.net.yourdomain.com' or the like. These people have done the reverse by adding some dots where they shouldn't have, leaving their domain name off some things that really need it.

(The net result is the same as in HowNotToDoDNSIX. I wonder how many people accept their email anyways? If all their email bounced, I'd have expected them to notice this problem by now.)

HowNotToDoDNSX written at 11:22:05; Add Comment


Page tools: See As Normal.
Search:
Login: Password:
Atom Syndication: Recent Pages, Recent Comments.

This dinky wiki is brought to you by the Insane Hackers Guild, Python sub-branch.