Solved

MX records incorrect on Dnsstuff.com, but are correct everywhere else?

Posted on 2008-10-03
11
925 Views
Last Modified: 2008-10-14
I am using Godaddy.com to host websites and DNS records for a number of sites.
Tests are being done at dnsstuff.com

Every site I have  is configured to use the same FQDN of our single mail server.  
When you perform a dnsstuff.com "dnsreport" the same FQDN will report 2 DIFFERENT IP addresses.  
All of my sites but 1 report the correct IP address and FQDN of the mail server.  

I contacted GoDaddy as this appeared to be a certain DNS problem on their end.  I ended up getting someone who knew what I was talking about and he advised that they had a "blown zone file" on the DNS server.  He said he was going to reload it, and I should be good in an hour.  Its been 30 hours now...and nothing has changed over at DNSStuff.com

I then used nslookup to query the nameservers listed at godaddy for the FQDN of the mail server.  They are correct at Godaddy...but aren't updating whatever DNS servers dnsstuff uses for themselves.

Also, some domains are having trouble sending email to the domain in question.

Most DNScheck sites on the web indicate the correct name/ip...but some do not.  

Is 30 hours not long enough to wait for propogation when the zone file is bad and their tech was mistaken when he said about an hour?  Or is there something worse going on here...?

Tips appreciated.
0
Comment
Question by:mikeshaver
  • 7
  • 4
11 Comments
 
LVL 3

Assisted Solution

by:DraconianSoul
DraconianSoul earned 500 total points
ID: 22639348
30 hours is too long.  I use GoDaddy for some stuff and their TTL is usually only about 15 minutes.  Whatever changes they made should have been reflected pretty quickly.

You can verify the TTL.  Run nslookup and connect to the godaddy servers (like you did when you checked the mail server information).  Set the type to SOA and then query your domain.  If the default TTL is less than 108000 (30 hours in seconds) theres another problem.  if it is too high, you should be able to set the TTL much lower, but unfortunately the setting wont take effect until after the TTL expires.
0
 
LVL 3

Assisted Solution

by:DraconianSoul
DraconianSoul earned 500 total points
ID: 22639355
Also... It could be the "blown" dns file had a malformed TTL.  You could query the SOA record for your domain from various other DNS servers and see what they have on record.
0
 
LVL 1

Author Comment

by:mikeshaver
ID: 22639400
Can you give me the commands to do the SOA verification from nslookup?

I've been typing this:
nslookup
server=ns51.domaincontrol.com  (the primary nameserver on the domain in question)

(but then it searches for a domain called server=ns51.domaincontrol.com).

?
0
 
LVL 3

Assisted Solution

by:DraconianSoul
DraconianSoul earned 500 total points
ID: 22639417
Let's try OpenDNS.org

Open your command prompt and run nslookup.  It will initially connect to your DNS server.
type 'server 208.67.222.222' to connect to opendns.org
then type 'set type=soa' to change to the soa query.
now type your domain name.  a few rows should result but look for either Default TTL or Minimum.  That's the length of time a DNS server will cache an entry before it bothers to look it up again.
0
 
LVL 1

Author Comment

by:mikeshaver
ID: 22639431
Non-authoritative answer:
<domain name>
primary nameserver = ns51.domaincontrol.com
responsible mail addr = dns.jomax.net
serial = 2008100200
refresh = 28800 <8 hours>
retry = 7200 <2 hours>
expire = 604800 <7 days>
Default TTL = 86400 <1 day>
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 
LVL 1

Author Comment

by:mikeshaver
ID: 22641229
Just checked again...been 40 hours now and its still incorrect at dnsstuff.com...and some clients cannot send email to this domain...yet others can without issue.
0
 
LVL 3

Assisted Solution

by:DraconianSoul
DraconianSoul earned 500 total points
ID: 22642336
I'm kinda running out of ideas...  when you log into your account at GoDaddy you can verify everything is configured correctly?  Would you mind providing the name of one of the domains?
0
 
LVL 1

Author Comment

by:mikeshaver
ID: 22642374
Me too.  Everything at Godaddy is right.  When you query their nameservers using nslookup, everything resolves correctly.  

It gets worse.  I made a new MX record for the domain and pointed it to the correct IP.  That worked, and DNS stuff showed the correct IP.  So I removed the old (incorrect IP) MX record.  That was about 4 hours ago.  I just checked at DNSstuff again, and now the newly created MX record is once again displaying the incorrect IP (but it showed up correctly a few hours ago!).

It seems that GoDaddy is perhaps propogating the wrong info...but when you query their name servers...its all correct!?
0
 
LVL 1

Author Comment

by:mikeshaver
ID: 22643394
I've made some changes.  I created a brand new A record on the destination domain.  

I pointed this A record to the correct IP of the mail server.  It seemed to work and propogate correctly for the last 6 hours.

So I added back in the "offending" mail server with a priority of 50.  As of right now, its showing the correct IP.  If it stays until morning...perhaps the issue is resolved.  If the secondary MX (pointed at the correct IP) reverts back to the odd/incorrect IP I think I will just nuke the secondary record and leave only the new primary one.  It will be different than every other one of our sites, but at least it appeared to be working.

I will report back in this thread.

I'll report back with results later tonight.
0
 
LVL 1

Accepted Solution

by:
mikeshaver earned 0 total points
ID: 22675261
I have resolved this by creating a replacement A record (with a different name than the incorrectly resolving one.  And of course pointed it to the correct IP.

Not sure why DNSStuff was reporting the wrong IP...but the above (although not optimum) has resolved the issue.

Thanks for everyone's comments.

0
 
LVL 1

Author Comment

by:mikeshaver
ID: 22679345
Issue resolved
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

This article explains how a domain name may be inadvertently appended to all DNS queries. This exhibits as described below. (CODE)And / Or: (CODE) Cause This issue can occur in either of these two scenarios. EITHER 1. A Primary DNS S…
Occasionally you run into the website or two that will not resolve properly using your own DNS servers.  Some people simply set up global forwarders for their DNS server.  I don’t recommend doing this because it can cause problems resolving addresse…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now