DNS problem - SERVFAIL for (seemingly) correctly replied names

There's one aspect that comes to my mind here:

In the (not so distant) past there were issues with Let's Encrypt returning misleading error messages (such as query timed out, or SERVFAIL messages) when it was in fact the Let's Encrypt software erroring out (e.g due to high load). Here's the thread for reference: Consistent "During secondary validation: DNS problem" between 01:00 UTC and 02:00 UTC? - #13 by jcjones

However that issue (turned out to be DNS queries getting dropped due to rate-limits) and the related misleading error messages should have been fixed already. So I wouldn't immediatly assume correlation. But I do think that spurious DNS error messages can still happen during high load times - for varying reasons potentially not related to previous things.

Can you reproduce these errors during any time of the day, or only during high-load times (which were last reported to spike at around 01:00 - 02:00 UTC)?

8 Likes