Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. queryNs ESERVFAIL on one domain only

queryNs ESERVFAIL on one domain only

Scheduled Pinned Locked Moved Solved Support
dnsdomainsunbound
5 Posts 2 Posters 413 Views 2 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N Offline
    N Offline
    nebsekhem
    wrote on last edited by joseph
    #1

    Hey,

    I've got a weird problem adding a domain name where it comes up with the error message "queryNs ESERVFAIL". I've tried a few suggestions on here to fix it but nothing about it makes sense. The domain is not new, nor have the nameservers been changed recently. I have tried adding it both manually and using a DigitalOcean token which both give the same error. Running host -t NS shows the correct nameservers and the existing A records point to the Cloudron server. I've tried restarting various services and even the whole server. It's only affecting this specific domain name though. I tried adding a different domain name using Manual DNS and that added with no problem, so I'm at a loss. Wonder if anyone can shed some light on this?

    1 Reply Last reply
    1
    • J Offline
      J Offline
      joseph
      Staff
      wrote on last edited by
      #2

      Can you check host -t NS domain.com 127.0.0.150 on the server? This is how Cloudron queries for nameservers .

      1 Reply Last reply
      0
      • N Offline
        N Offline
        nebsekhem
        wrote on last edited by
        #3

        I get not found: 2(SERVFAIL) when I specify 127.0.0.150. If I don't specify that it shows the correct DNS servers. The domain resolves, it even loads the default cloudron page.

        1 Reply Last reply
        1
        • J Offline
          J Offline
          joseph
          Staff
          wrote on last edited by
          #4

          @nebsekhem 127.0.0.150 is the internal unbound DNS. When you don't specify it, it uses the system DNS.

          Can you try disabling DNSSEC or maybe forwarding queries for that specific domain to your other DNS server ? See https://docs.cloudron.io/networking/#dns

          1 Reply Last reply
          0
          • J joseph marked this topic as a question on
          • N Offline
            N Offline
            nebsekhem
            wrote on last edited by
            #5

            So it turns out DNSSEC is the problem. Unbeknownst to me, the previous registrar had enabled DNSSEC by default, when I transferred the domain some time ago, the records were not removed when the new registrar updated the nameservers. As they don't have DNSSEC management and my DNS resolver doesn't validate DNSSEC, I didn't notice anything was amiss.
            Thank you for your help with this!

            1 Reply Last reply
            1
            • J joseph has marked this topic as solved on
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Don't have an account? Register

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • Bookmarks
            • Search