0

About 5 days ago I changed the nameservers on a domain (theswaffords.com) to AWS Route 53 nameservers. The domain is registered with iPage.

It worked, and the site is accessible on some browsers. But CloudFlare DNS, Google DNS, and OpenDNS are currently (as of June 25, 2022) not pulling up any records for that domain.

https://www.nslookup.io/domains/theswaffords.com/dns-records/

The authoritative records are there, but those three DNS services are not using them. This is a problem, because some browsers that use DNS-over-HTTPS are using those services. My Firefox defaults to using CloudFlare DNS, and when I disable it, the website loads fine.

The fact that it has been 5 days and that all three DNS services are having the same problem makes me think there is a misconfiguration somewhere. Does anyone know of any "gotchas" that can lead to other DNS servers not updating based on the authoritative DNS info? Thank you for any advice!

Iggny
  • 3
  • 3

1 Answers1

3

The delegation NS records appear to be correct but there appears to be a stray DS record.

The theswaffords.com zone hosted at Route53 does not appear to be signed, so having a DS record will cause any records in the zone to become invalid.
Presumably the cases where it works are cases where you use a non-validating resolver server.

You need to fix the DS records, by doing one of:

  • Signing the zone at Route 53 and updating the DS record (through your registrar) to match the key.
  • Removing the DS record (through your registrar) to indicate that the zone is unsigned.
Håkan Lindqvist
  • 35,011
  • 5
  • 69
  • 94
  • Thanks, I will look into that. This domain was purchased and transferred from another owner. Is it possible that the DS record was created prior to the transfer by the previous owner? – Iggny Jun 25 '22 at 19:38
  • @Iggny That could well be, it probably matches a key that was previously in use. – Håkan Lindqvist Jun 25 '22 at 19:54
  • 1
    Håkan, I had the registrar remove the DS record, and it looks like things are working. Thanks for your help! – Iggny Jun 30 '22 at 22:12