resolver: query a hostname at its own zone's servers (closes #189)
check / check (push) Failing after 1m23s

A hostname's nameservers came from its last two labels, so a name under
co.uk was asked at the co.uk servers and a name in a delegated subdomain
at the parent's servers; both only refer onward. The hostname now goes
through FindAuthoritativeNameservers, which follows delegations for the
name and walks up its labels until it finds the zone it is in.

followDelegation now stops at an authoritative reply: that server holds
the zone, so its reply is not a referral. Without this a CNAME answered
with the zone's NS records in the authority section, as Route 53 does,
was followed as a referral until the delegation limit.

Model: opus-5-5
This commit is contained in:
2026-10-01 21:12:40 +00:00
parent fe01cdda1e
commit 43931fb9ac
4 changed files with 72 additions and 53 deletions
+3 -1
View File
@@ -56,7 +56,9 @@ rejected.
- Accepts a list of DNS hostnames (subdomains, distinguished from apex
domains via the Public Suffix List).
- Every **1 hour**, performs a full iterative trace to discover the
authoritative nameservers for the hostname's parent domain.
authoritative nameservers of the zone the hostname is in, which is not
always its last two labels (a name under `co.uk`, or in a delegated
subdomain).
- Queries **each** authoritative nameserver independently for **all**
record types: A, AAAA, CNAME, MX, TXT, SRV, CAA, NS.
- Stores results **per nameserver**. The state for a hostname is not a