# DNS problem: NXDOMAIN looking up TXT for

**URL:** <https://community.letsencrypt.org/t/dns-problem-nxdomain-looking-up-txt-for/80691>\
**Category:** Server\
**Created:** [December 21, 2018, 6:48pm UTC](https://community.letsencrypt.org/t/dns-problem-nxdomain-looking-up-txt-for/80691 "2018-12-21T18:48:48Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![glapalomento](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/glapalomento/32/28393_2.png) [@glapalomento](https://community.letsencrypt.org/u/glapalomento)\
**Post date:** [December 21, 2018, 6:48pm UTC](https://community.letsencrypt.org/t/dns-problem-nxdomain-looking-up-txt-for/80691/1 "2018-12-21T18:48:48Z")

</div>

Attempted:  
certbot certonly -a manual --preferred-challenges dns -d [subseasolutions.net](http://subseasolutions.net) -d [www.subseasolutions.net](http://www.subseasolutions.net)

Results:  
Saving debug log to /var/log/letsencrypt/letsencrypt.log

Plugins selected: Authenticator manual, Installer None

Obtaining a new certificate

Performing the following challenges:

dns-01 challenge for [subseasolutions.net](http://subseasolutions.net)

dns-01 challenge for [www.subseasolutions.net](http://www.subseasolutions.net)

* * *

NOTE: The IP of this machine will be publicly logged as having requested this

certificate. If you’re running certbot in manual mode on a machine that is not

your server, please ensure you’re okay with that.

Are you OK with your IP being logged?

* * *

(Y)es/(N)o: y

* * *

Please deploy a DNS TXT record under the name

\_acme-challenge.subseasolutions.net with the following value:

q\_Iehior2uERZwrZ-wx5f8lLoX9D9T-Z4BqyIpIZO3g

Before continuing, verify the record is deployed.

* * *

Press Enter to Continue

* * *

Please deploy a DNS TXT record under the name

\_acme-challenge.www.subseasolutions.net with the following value:

8LEBJofPi33j33ExL7tQN8To5kO2iSJg6JQRB0P2m\_0

Before continuing, verify the record is deployed.

(This must be set up in addition to the previous challenges; do not remove,

replace, or undo the previous challenge tasks yet. Note that you might be

asked to create multiple distinct TXT records with the same name. This is

permitted by DNS standards.)

* * *

Press Enter to Continue

Waiting for verification…

Cleaning up challenges

Failed authorization procedure. [subseasolutions.net](http://subseasolutions.net) (dns-01): urn:ietf:params:acme:error:dns :: DNS problem: NXDOMAIN looking up TXT for \_acme-challenge.subseasolutions.net, [www.subseasolutions.net](http://www.subseasolutions.net) (dns-01): urn:ietf:params:acme:error:dns :: DNS problem: NXDOMAIN looking up TXT for \_acme-challenge.www.subseasolutions.net

**IMPORTANT NOTES:**

- The following errors were reported by the server:

Domain: [subseasolutions.net](http://subseasolutions.net)

Type: None

Detail: DNS problem: NXDOMAIN looking up TXT for

\_acme-challenge.subseasolutions.net

Domain: [www.subseasolutions.net](http://www.subseasolutions.net)

Type: None

Detail: DNS problem: NXDOMAIN looking up TXT for

\_acme-challenge.www.subseasolutions.net

NOTE: I did add the TXT records to the DNS prior to attempting this.  
Any help appreciated!

---

<div class="post-metadata">

**Author:** ![stevenzhu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/stevenzhu/32/18864_2.png) [@stevenzhu](https://community.letsencrypt.org/u/stevenzhu)\
**Post date:** [December 21, 2018, 6:53pm UTC](https://community.letsencrypt.org/t/dns-problem-nxdomain-looking-up-txt-for/80691/2 "2018-12-21T18:53:27Z")

</div>

Hi,

Did you enter those records inside your GoDaddy DNS?

Thank you

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [December 21, 2018, 7:03pm UTC](https://community.letsencrypt.org/t/dns-problem-nxdomain-looking-up-txt-for/80691/3 "2018-12-21T19:03:03Z")

</div>

Hi @glapalomento

> [@glapalomento](#):
>
> NOTE: I did add the TXT records to the DNS prior to attempting this.

I can't see your txt records:

* * *

### TXT - Entries

| Domainname | TXT Entry | Status | ∑ Queries | ∑ Timeout |
| --- | --- | --- | --- | --- |
| [subseasolutions.net](http://subseasolutions.net) | v=spf1 a:dispatch-us.ppe-hosted.com ~all | ok | 1 | 0 |
| [subseasolutions.net](http://subseasolutions.net) | ppe-282374e8a9c2b6e231d3 | ok | 1 | 0 |
| [www.subseasolutions.net](http://www.subseasolutions.net) | v=spf1 a:dispatch-us.ppe-hosted.com ~all | ok | 1 | 0 |
| [www.subseasolutions.net](http://www.subseasolutions.net) | ppe-282374e8a9c2b6e231d3 | ok | 1 | 0 |
| \_acme-challenge.subseasolutions.net | | Name Error - The domain name does not exist | 1 | 0 |
| \_acme-challenge.www.subseasolutions.net | | Name Error - The domain name does not exist | 1 | 0 |
| \_acme-challenge.subseasolutions.net.subseasolutions.net | | Name Error - The domain name does not exist | 1 | 0 |
| \_acme-challenge.www.subseasolutions.net.www.subseasolutions.net | | Name Error - The domain name does not exist | 1 | 0 |

* * *

You have txt entries. But not the required versions. `_acme-challenge.subseasolutions.net` and `_acme-challenge.www.subseasolutions.net` are required.

You didn't create typical wrong entries (the last two), this is good.

---

<div class="post-metadata">

**Author:** ![glapalomento](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/glapalomento/32/28393_2.png) [@glapalomento](https://community.letsencrypt.org/u/glapalomento)\
**Post date:** [December 21, 2018, 7:29pm UTC](https://community.letsencrypt.org/t/dns-problem-nxdomain-looking-up-txt-for/80691/4 "2018-12-21T19:29:27Z")

</div>

Sorry, but I did enter them but I removed them since trying. I will do it again so you can test. Thank you!

---

<div class="post-metadata">

**Author:** ![glapalomento](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/glapalomento/32/28393_2.png) [@glapalomento](https://community.letsencrypt.org/u/glapalomento)\
**Post date:** [December 21, 2018, 7:32pm UTC](https://community.letsencrypt.org/t/dns-problem-nxdomain-looking-up-txt-for/80691/5 "2018-12-21T19:32:57Z")

</div>

OK, I tried it again and got same results. This time I have left the TXT entries in the Godaddy acct.

Please deploy a DNS TXT record under the name  
\_acme-challenge.subseasolutions.net with the following value:

XkuohdHqYLDCYxkFBLF7t1jWqCe8EI60a1sSnpARZrU

Before continuing, verify the record is deployed.

* * *

Press Enter to Continue

* * *

Please deploy a DNS TXT record under the name  
\_acme-challenge.www.subseasolutions.net with the following value:

sUIQgdUdUrENlG3k897WsMFqchWTf6DNEBF3GLfzLxY

Before continuing, verify the record is deployed.  
(This must be set up in addition to the previous challenges; do not remove,  
replace, or undo the previous challenge tasks yet. Note that you might be  
asked to create multiple distinct TXT records with the same name. This is  
permitted by DNS standards.)

* * *

Press Enter to Continue  
Waiting for verification…  
Cleaning up challenges  
Failed authorization procedure. [subseasolutions.net](http://subseasolutions.net) (dns-01): urn:ietf:params:acme:error:dns :: DNS problem: NXDOMAIN looking up TXT for \_acme-challenge.subseasolutions.net, [www.subseasolutions.net](http://www.subseasolutions.net) (dns-01): urn:ietf:params:acme:error:dns :: DNS problem: NXDOMAIN looking up TXT for \_acme-challenge.www.subseasolutions.net

IMPORTANT NOTES:

- The following errors were reported by the server:

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [December 21, 2018, 7:40pm UTC](https://community.letsencrypt.org/t/dns-problem-nxdomain-looking-up-txt-for/80691/6 "2018-12-21T19:40:05Z")

</div>

> [@glapalomento](#):
>
> Please deploy a DNS TXT record under the name  
> \_acme-challenge.subseasolutions.net with the following value:

Now it's the wrong domain name (using [subseasolutions.net - Make your website better - DNS, redirects, mixed content, certificates](https://check-your-website.server-daten.de/?q=subseasolutions.net) ):

### TXT - Entries

| Domainname | TXT Entry | Status | ∑ Queries | ∑ Timeout |
| --- | --- | --- | --- | --- |
| [subseasolutions.net](http://subseasolutions.net) | v=spf1 a:dispatch-us.ppe-hosted.com ~all | ok | 1 | 0 |
| [subseasolutions.net](http://subseasolutions.net) | ppe-282374e8a9c2b6e231d3 | ok | 1 | 0 |
| \_acme-challenge.subseasolutions.net | | Name Error - The domain name does not exist | 1 | 0 |
| \_acme-challenge.subseasolutions.net.subseasolutions.net | XkuohdHqYLDCYxkFBLF7t1jWqCe8EI60a1sSnpARZrU | perhaps wrong | 1 | 0 |

* * *

You have created one entry with `_acme-challenge.subseasolutions.net.subseasolutions.net`.

So your context adds your domain name. So add only `_acme-challenge` and `_acme-challenge.www` as domain name.

---

<div class="post-metadata">

**Author:** ![glapalomento](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/glapalomento/32/28393_2.png) [@glapalomento](https://community.letsencrypt.org/u/glapalomento)\
**Post date:** [December 21, 2018, 7:46pm UTC](https://community.letsencrypt.org/t/dns-problem-nxdomain-looking-up-txt-for/80691/7 "2018-12-21T19:46:51Z")

</div>

Oh, wow. I was basically just copying the line and didn’t realize I needed to leave the domain off. Thanks so much. This is now resolved.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [December 21, 2018, 11:13pm UTC](https://community.letsencrypt.org/t/dns-problem-nxdomain-looking-up-txt-for/80691/8 "2018-12-21T23:13:12Z")

</div>

You would think that all large scale DNS systems would have logic programed in that can check for such situations; and ask for you to reconfirm.

_Are you sure you want to add record: `_acme-challenge.subseasolutions.net.subseasolutions.net`_  
_[The new record would contain the domain twice]_

But hey it’s only (almost) 2019 - machines have not acquired intelligence yet - LOL

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [January 20, 2019, 11:13pm UTC](https://community.letsencrypt.org/t/dns-problem-nxdomain-looking-up-txt-for/80691/9 "2019-01-20T23:13:21Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
