google dns cannot resolve my domain

421 views
Skip to first unread message

egateme...@gmail.com

unread,
May 11, 2016, 5:14:56 PM5/11/16
to public-dns-discuss
Dear all,

This happen since last Friday

below is the result of my diagnosis, appreciate for your help. Thanks & Regards

>nslookup egate.my 8.8.8.8
Address: 8.8.8.8

DNS request timed out.
        timeout was 2 seconds
DNS request timed out.
        timeout was 2 seconds
*** Request to google-publi-dns-a.google.com timed-out

>nslookup egate.my 208.67.222.222
Address: 208.67.222.222

Non-authoritative answer:
Name: egate.my
Address: 175.143.96.82

Message has been deleted

Alex Dupuy

unread,
May 11, 2016, 5:49:58 PM5/11/16
to public-dns-discuss
Your queries are exiting Google's infrastructure from one of our resolvers; you can see which one by running the command `dig TXT o-o.myaddr.l.google.com` or `nslookup -q=txt o-o.myaddr.l.google.com` and checking the address against the list at https://developers.google.com/speed/public-dns/faq#locations

I'm pretty sure that this location will be "sin" (Singapore), as it is close to your location in (presumably) Malaysia. Our resolvers in Singapore are getting timeouts from the afraid.org authoritative nameservers located in the US (California, Nevada, Texas, and Virginia).

I would strongly recommend that you set up additional secondary nameservers for your domain (dns.he.net offers very good coverage, and is free) - you would need to enter the he.net nameserver IP (216.218.130.2) to the AXFR-ALLOW list at http://freedns.afraid.org/secondary/axfr-ip.php (See https://forums.he.net/index.php?topic=1006.0 and elsewhere at dns.he.net for instructions about that side). Then you would need to add the additional afraid.org and he.net nameservers to your egate.my registration (you currently only have ns1/2.afraid.org).

This expanded nameserver configuration will improve the reliability and lookup speed for your domain not only through Google Public DNS, but worldwide through any resolver.

In the meantime I will also contact our network team to try to understand why we cannot reach afraid.org's AS36351 from our Singapore datacenter, and the afraid.org administration to see if they are perhaps blocking queries from 173.194.90.* and 2404:6800:4003::/48

Alex Dupuy

unread,
May 12, 2016, 2:59:27 PM5/12/16
to public-dns-discuss
I just checked and it seems that our resolvers in Singapore are once again able to reach the afraid.org nameservers in AS36351, so your domains should be resolving through Google Public DNS again.  Please let us know if that is not the case.

jason...@gmail.com

unread,
May 17, 2016, 10:54:00 AM5/17/16
to public-dns-discuss
It seems the problem is still there (perhaps intermittent).

I have a dynamic pointer to my home server as a subdomain of mooo.com (one of afraid.org's domains), and it is resolving from OpenDNS and Level3 resolvers, but @8.8.8.8 and @8.8.4.4 are giving SERVFAIL from Malaysia. But if I ssh to a server in the US they are resolving from there, so it seems to be this same localized problem with the Singapore resolvers.

`dig TXT o-o.myaddr.l.google.com @8.8.8.8` confirms that the Singapore resolvers are being used:

;; QUESTION SECTION:

;; ANSWER SECTION:
o-o.myaddr.l.google.com. 59 IN TXT "74.125.190.7"
o-o.myaddr.l.google.com. 59 IN TXT "edns0-client-subnet 192.228.139.243/32"


Reply all
Reply to author
Forward
0 new messages