# CAA SERVFAIL changes

**URL:** https://community.letsencrypt.org/t/caa-servfail-changes/38298
**Category:** API Announcements
**Created:** [July 17, 2017, 6:00pm UTC](https://community.letsencrypt.org/t/caa-servfail-changes/38298 "2017-07-17T18:00:46Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)
#### Post date: [July 21, 2017, 8:24am UTC](https://community.letsencrypt.org/t/caa-servfail-changes/38298/2 "2017-07-21T08:24:33Z")

</div>

Note: [there is a bug](https://github.com/PowerDNS/pdns/issues/5546) in PowerDNS versions 4.0.3 and below that will cause SERVFAIL problems.

> [@](#):
>
> This was fixed in git master by [#5377](https://github.com/PowerDNS/pdns/pull/5377), which was backported to 4.0.x in [#5378](https://github.com/PowerDNS/pdns/pull/5378) and then released as 4.0.4. In other words, affected users running 4.0.3 or lower should upgrade to 4.0.4 and try again. Users running master should not be affected today.

If you are a DNS operator and you use PowerDNS, please upgrade to 4.0.4. If you do not operate your DNS and want to check if your DNS operator uses PowerDNS, you can in some cases check the version string. First, find out what your nameservers are:

```nohighlight
$ dig +short ns YOUR_BASE_DOMAIN_NAME
ns1.example.net.
ns2.example.net.

```

Pick one of the returned nameservers, for instance `ns2.example.net`, and run this query (replacing `ns2.example.net` with one of the nameservers found from the above command):

```nohighlight
$ dig +short version.bind chaos txt @ns2.example.net
"PowerDNS Authoritative Server 4.0.4 (built Jun 22 2017 20:14:47 by buildbot@c1b965951e5b)"

```

If you are getting CAA SERVFAIL errors, and this shows PowerDNS 4.0.3 or less, please contact your DNS operator to upgrade. Note that some servers may not allow querying version information. If you don't get results, or just get "Served by PowerDNS - [http://www.powerdns.com](http://www.powerdns.com)", then default to contacting your DNS operator. If you aren't sure who your DNS operator is, ask your hosting provider.

Also note: Because this bug only manifests on empty responses, you may be able to work around it by adding a CAA record to your zone that authorizes issuance for Let's Encrypt. CAA is [supported by PowerDNS since 4.0.0](https://doc.powerdns.com/md/types/#caa). If your nameservers are running earlier versions than that, you may also be able to work around by adding a CNAME to a domain name whose authoritative nameserver runs different software, and adding a CAA record authorizing issuance there.

---

_[View the full topic](https://community.letsencrypt.org/t/caa-servfail-changes/38298)._
