Diagnose mail DNS failures
Separate authoritative errors, cache staleness, and delegation problems.
Objective
Diagnose DNS resolution failures
Identify NXDOMAIN, wrong targets, stale cache, and authority problems affecting mail DNS.
Starting state
Mail or authentication lookups are failing
Prerequisites
- Failing name and symptom
Estimated time
1–2 hours
Difficulty
intermediate
Required access
- Ability to query authoritative and recursive resolvers
Inputs
- Domain
- Failing record type
- Resolver path if known
Step-by-step instructions
- Query the authorityAsk authoritative servers directly for the RRset.
- Compare recursive answersCheck whether recursive resolvers still cache prior data.
- Inspect delegationValidate NS and glue if authority cannot be reached cleanly.
Verification
- Root cause classified with evidence
Common mistakes
- Cannot reach any authoritative server
- Authority wrong vs cache stale vs delegation broken
Rollback / recovery
- N/A — diagnosis
Expected outcome
Failure class identified with next remediation step.
When to escalate
- Registry/registrar delegation inconsistency