Tony Finch dot at dotat.at
Tue Apr 6 19:55:03 UTC 2021

Seth Mattinen <sethm at rollernet.us> wrote:
> I'm beginning to think this is a DNSSEC related problem, I'll ask on the
> pdns-users list. I see it's asking for a DS record on
> login.authorize.net.cdn.cloudflare.net when the nearest one appears to be at
> cloudflare.net, so for some reason that's not being applied all the way down.

The probem is that your resolver is trying to prove that
login.authorize.net.cdn.cloudflare.net isn't a delegation point by
querying for its DS record(s). The Cloudflare authoritative DNS servers
return a SERVFAIL for this query, so your resolver isn't able to validate
the answer.

(I also replied on the pdns-users list)

