issue with ECS/EDNS0 and google dns not passing info

515 views
Skip to first unread message

Rob Canis

unread,
Oct 11, 2020, 11:14:26 PM10/11/20
to public-dns-discuss
I seem to be having an issue with google not passing on edns information to my servers.  I can force it if I do a +trace option, but if I do not, I get all kinds of answers because google tosses me all over the USA for resolvers.  This I can normally live with, but I have people in India that are getting west coast US resolvers and that's just not working.

Is there something I need to do with google to get on some whitelist or fix my dns servers (and don't say I need ipv6, that's just a non-starter at this time).

Thanks in advance!

Alex Dupuy

unread,
Oct 15, 2020, 2:10:34 AM10/15/20
to public-dns-discuss
If you are not getting EDNS0 at all from Google Public DNS that would be very surprising.

If you are not getting ECS from Google Public DNS, your authoritative server is probably not following all of the requirements described at https://developers.google.com/speed/public-dns/docs/ecs.

Check that your authoritative name servers are properly implementing ECS for all queries (even if you are not returning geo-located answers for them).
 
Is there something I need to do with google to get on some whitelist or fix my dns servers (and don't say I need ipv6, that's just a non-starter at this time).

Your name servers do not have to be on IPv6, but you do need to properly handle IPv6 addresses in ECS (and this may be the reason for the problems you are having).
 

Kisalaya Prasad

unread,
Oct 15, 2020, 10:33:04 PM10/15/20
to public-dns-discuss
Hi,

We can look into it in more detail, but we will need more info from you. 
What is the domain name you are trying to resolve for ? 


thanks,
Kisalaya

Rob Canis

unread,
Oct 16, 2020, 4:25:38 PM10/16/20
to public-dns-discuss

Damian Zielinski

unread,
Oct 16, 2020, 4:25:47 PM10/16/20
to Kisalaya Prasad, public-dns-discuss
--
You received this message because you are subscribed to the Google Groups "public-dns-discuss" group.
To unsubscribe from this group and stop receiving emails from it, send an email to public-dns-discuss+unsub...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/public-dns-discuss/400b864e-d322-4bb7-be52-3bae4e936f9dn%40googlegroups.com.

Rob Canis

unread,
Oct 23, 2020, 10:56:30 AM10/23/20
to public-dns-discuss
anyone have any luck?

Rob Canis

unread,
Oct 29, 2020, 3:28:40 PM10/29/20
to public-dns-discuss
still looking for help.

On Thursday, October 15, 2020 at 10:33:04 PM UTC-4 kisa...@google.com wrote:

Tianhao Chi

unread,
Oct 29, 2020, 5:19:25 PM10/29/20
to public-dns-discuss
Can you also provide a valid ECS in a valid CIDR format for us to look it up?

Rob Canis

unread,
Nov 2, 2020, 12:17:12 PM11/2/20
to public-dns-discuss
you can almost pick anything you want.  I have almost a dozen sites set up.  If you really need something specific, try 167.246.60.1 That should get you an 'east' answer.

Rob Canis

unread,
Nov 15, 2020, 9:57:18 PM11/15/20
to public-dns-discuss
anything folks?  167.246.60.1/24 is a pretty good example of what to look for.

Tianhao Chi

unread,
Nov 30, 2020, 5:44:25 PM11/30/20
to public-dns-discuss
I have looked it up in our internal debugging tool. ECS is always forwarded but it looks like ECS is requested but not received in nameserver's response.

Puneet Sood

unread,
Dec 1, 2020, 9:33:40 AM12/1/20
to Rob Canis, public-dns-discuss
On Sun, Nov 15, 2020 at 9:57 PM Rob Canis <rjc...@gmail.com> wrote:
>
> anything folks? 167.246.60.1/24 is a pretty good example of what to look for.
See the update in https://issuetracker.google.com/issues/173139531.
> --
> You received this message because you are subscribed to the Google Groups "public-dns-discuss" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to public-dns-disc...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/public-dns-discuss/f2e5d358-1c8a-4c88-bd0e-1d69aa13bb44n%40googlegroups.com.

hemant burman

unread,
Jul 28, 2021, 9:15:10 AM7/28/21
to public-dns-discuss

Hello, did you get a response on ticket 173139531, I am having the same issue, but do not have permission to see the resolution in the ticket
Thanks

Rob Canis

unread,
Jul 28, 2021, 1:24:37 PM7/28/21
to public-dns-discuss
Nope.  Never did resolve the issue.  I gave up and went with Akamai.  I'm very disappointed in google for this issue.  Actually most of the industry.  I just couldn't win on this.
Reply all
Reply to author
Forward
0 new messages