Site not resolving uniformly
My site www.acurent.com is not resolving to its IP address 23.20.46.124 uniformly
Check on: https://www.whatsmydns.net/#A/acurent.com, it shows that its resolving for certain networks only. If you refresh the page after 5-10 mins, it will show you a different set of servers which resolve the domain and the previous ones dont.
Background: I got this domain from a reseller on Sedo and this problem is persisting from the time the domain was transferred to my account. It has been 3 weeks now.
I have tried using 4 different internet connections at home and it is opening only via one. Also tried using VPNs worldover and the behavior is non consistent.
Upon further investigation, it looks like the nameservers aren't being propagated effectively.
See here: https://www.whatsmydns.net/#NS/acurent.com
Following is the result from opendns cache check tool. If this does not resolve on OpenDNS, then there is definitely a problem somewhere:
https://snipboard.io/HJehKj.jpg
Also google's DNS tool gives me this error:
https://snipboard.io/znPbLX.jpg
I have setup servers and DNS for over more than 10 years but I'm at my wits end on this. I would really appreciate it if someone could help me get to the bottom of this problem.
It looks like this domain is in a broken state in terms of DNSSEC validation where ideally it should not resolve at all. (SERVFAIL
status is the expected outcome for any validating resolver.)
If you look at for instance DNSViz output, you can see that the delegation has a DS
record (specifies a DNSSEC key that is used for signing the zone) which refers to a key with tag 20198
but there does not appear to be any keys at all in the zone (so no key 20198
to be found), and there seems to be no signing going on.
You probably want to update (potentially remove?) the DS
record for the zone to match your actual expectations for DNSSEC signing. This would be done through the registrar.