A name gets a parent zone's nameservers when finding its own fails: a domain that does not exist shows the .com servers #222

Closed
opened 2026-10-02 07:35:33 +02:00 by clawbot · 1 comment
Collaborator

Found in the trial run for #149.

When finding a name's nameservers fails, dnswatcher tries the name's parent, then the parent's parent, and uses the first nameservers it finds. It does this whatever the failure was, not only when the name turned out to have no delegation of its own. Two results in the run:

  • dnswatcher-trial-nonexistent-149.com, a domain that does not exist, was shown on the dashboard and in /api/v1/status with the 13 .com servers (a.gtld-servers.net. to m.gtld-servers.net.) as its nameservers, each with status error. Nothing said that the domain does not exist, which is what the .com servers answered. The README says a domain's NS record set is the one "its parent zone's servers delegate"; a domain that does not exist has none.
  • pool.ntp.org switched more than once between its own nameservers (a.ntpns.org. to i.ntpns.org.) and the ntp.org servers (anyns.pch.net., dns1.udel.edu., dns2.udel.edu., ns1.everett.org.), which only refer it on and so were saved with status error and "server returned a referral". The walk to pool.ntp.org can ask only ns1.everett.org. (#221), so one unanswered query there is enough to make it fail.

To see it, watch a .com domain that does not exist. FindAuthoritativeNameservers in internal/resolver/iterative.go moves to the next parent name whenever followDelegation returns an error.

Definition of done

  • A domain's nameservers are only ever its own delegation. A domain whose parent zone says it does not exist has no nameservers, and if it had some on the previous check, that is an NS Change notification with all of them removed. README "DNS Domain Monitoring" says so.
  • A hostname moves to a parent name only when the servers asked answered that the name has no delegation of its own. A walk that fails because servers did not answer is a failed check of that name, not a reason to use a parent zone's nameservers.
  • Tests against live DNS, no stand-in resolver: a .com domain that does not exist gets no nameservers; a hostname in a delegated subdomain still gets that subdomain's nameservers.

Model: opus-5-5

Found in the trial run for https://git.eeqj.de/sneak/dnswatcher/issues/149. When finding a name's nameservers fails, dnswatcher tries the name's parent, then the parent's parent, and uses the first nameservers it finds. It does this whatever the failure was, not only when the name turned out to have no delegation of its own. Two results in the run: - `dnswatcher-trial-nonexistent-149.com`, a domain that does not exist, was shown on the dashboard and in `/api/v1/status` with the 13 `.com` servers (`a.gtld-servers.net.` to `m.gtld-servers.net.`) as its nameservers, each with status `error`. Nothing said that the domain does not exist, which is what the `.com` servers answered. The README says a domain's NS record set is the one "its parent zone's servers delegate"; a domain that does not exist has none. - `pool.ntp.org` switched more than once between its own nameservers (`a.ntpns.org.` to `i.ntpns.org.`) and the `ntp.org` servers (`anyns.pch.net.`, `dns1.udel.edu.`, `dns2.udel.edu.`, `ns1.everett.org.`), which only refer it on and so were saved with status `error` and "server returned a referral". The walk to `pool.ntp.org` can ask only `ns1.everett.org.` (https://git.eeqj.de/sneak/dnswatcher/issues/221), so one unanswered query there is enough to make it fail. To see it, watch a `.com` domain that does not exist. `FindAuthoritativeNameservers` in `internal/resolver/iterative.go` moves to the next parent name whenever `followDelegation` returns an error. ## Definition of done - A domain's nameservers are only ever its own delegation. A domain whose parent zone says it does not exist has no nameservers, and if it had some on the previous check, that is an NS Change notification with all of them removed. README "DNS Domain Monitoring" says so. - A hostname moves to a parent name only when the servers asked answered that the name has no delegation of its own. A walk that fails because servers did not answer is a failed check of that name, not a reason to use a parent zone's nameservers. - Tests against live DNS, no stand-in resolver: a `.com` domain that does not exist gets no nameservers; a hostname in a delegated subdomain still gets that subdomain's nameservers. Model: opus-5-5
clawbot added this to the 1.0 milestone 2026-10-02 07:35:33 +02:00
Author
Collaborator

#250: a domain's NS set is now only its own delegation, empty when its parent zone's servers answer that it does not exist, which the watcher reports as an NS Change with every nameserver removed. A hostname moves to a parent name only on an authoritative answer that it has no delegation; when its servers do not answer, the check fails. A domain with no delegation still has its own records asked at the servers of the zone it is in (for a .com domain that does not exist, the .com servers).

Model: opus-5-5

https://git.eeqj.de/sneak/dnswatcher/pulls/250: a domain's NS set is now only its own delegation, empty when its parent zone's servers answer that it does not exist, which the watcher reports as an NS Change with every nameserver removed. A hostname moves to a parent name only on an authoritative answer that it has no delegation; when its servers do not answer, the check fails. A domain with no delegation still has its own records asked at the servers of the zone it is in (for a `.com` domain that does not exist, the `.com` servers). Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/dnswatcher#222