I have a recursive caching BIND/named setup and it does not want to resolve some domains. I see those errors in logfile:
Dec 22 11:53:02 router2.lan named[301]: skipping nameserver 'ns0.flowerfire.com' because it is a CNAME, while resolving 'www.sawmill.net/AAAA'
Dec 22 11:53:02 router2.lan named[301]: SERVFAIL unexpected RCODE resolving 'www.sawmill.net/A/IN': 63.249.66.124#53
Dec 22 11:53:02 router2.lan named[301]: skipping nameserver 'ns0.flowerfire.com' because it is a CNAME, while resolving 'www.sawmill.net/A'
Dec 22 11:53:02 router2.lan named[301]: skipping nameserver 'ns1.flowerfire.com' because it is a CNAME, while resolving 'www.sawmill.net/A'
Dec 22 11:53:02 router2.lan named[301]: SERVFAIL unexpected RCODE resolving 'www.sawmill.net/AAAA/IN': 63.249.66.124#53
Dec 22 11:53:02 router2.lan named[301]: skipping nameserver 'ns0.flowerfire.com' because it is a CNAME, while resolving 'www.sawmill.net/AAAA'
Dec 22 11:53:02 router2.lan named[301]: skipping nameserver 'ns1.flowerfire.com' because it is a CNAME, while resolving 'www.sawmill.net/AAAA'
(that domain is not mine)
Google's 8.8.8.8 resolves this domain properly
Here's my named.conf
options {
directory "/var/named";
pid-file "/run/named/named.pid";
listen-on-v6 { any; };
dnssec-validation auto;
auth-nxdomain no;
allow-query {
any;
};
recursion yes;
allow-recursion {
any;
};
allow-transfer { none; };
allow-update { none; };
version none;
hostname none;
server-id none;
max-cache-size 16M;
max-ncache-ttl 3600;
};
And BIND version:
BIND 9.11.0-P1
Does anyone know why is that happening?
By the way, the server is firewalled so no harm in allowing recursion from all sources.