How not to set up your DNS (part 10)

August 21, 2006

This one is a close variation of HowNotToDoDNSIX, but it earns extra points for making the reverse error from a common one. Presented in semi-illustrated format:

; dig +short ns system-bank.net.
dns01.system-bank.net.
dns02.system-bank.net.

(At this point I will pause to note that dns01.system-bank.net and dns02.system-bank.net have the same IP address, 218.227.163.13, a trick that was featured back at the start of this series.)

; dig a server.system-bank.net. @218.227.163.13
[...]
;; AUTHORITY SECTION:
system-bank.net. IN NS dns01.
system-bank.net. IN NS dns02.

(TTLs have been omitted for clarity.)

The usual error is for people to leave out the trailing dot on things like NS records pointing to external machines, so that you get an NS record of 'ns1.other.net.yourdomain.com' or the like. These people have done the reverse by adding some dots where they shouldn't have, leaving their domain name off some things that really need it.

(The net result is the same as in HowNotToDoDNSIX. I wonder how many people accept their email anyways? If all their email bounced, I'd have expected them to notice this problem by now.)

Written on 21 August 2006.
« Finally, a good reason to periodically reboot servers
Most new products are upgrades »

Page tools: View Source, Add Comment.
Search:
Login: Password:
Atom Syndication: Recent Comments.

Last modified: Mon Aug 21 11:22:05 2006
This dinky wiki is brought to you by the Insane Hackers Guild, Python sub-branch.