# DNS resolver issues?

**URL:** <https://community.letsencrypt.org/t/dns-resolver-issues/10487>\
**Category:** Issuance Tech\
**Created:** [February 8, 2016, 9:45pm UTC](https://community.letsencrypt.org/t/dns-resolver-issues/10487 "2016-02-08T21:45:12Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrtux](https://avatars.discourse-cdn.com/v4/letter/m/9de0a6/32.png) [@mrtux](https://community.letsencrypt.org/u/mrtux)\
**Post date:** [February 8, 2016, 9:45pm UTC](https://community.letsencrypt.org/t/dns-resolver-issues/10487/1 "2016-02-08T21:45:12Z")

</div>

It’s the first time I have to renew my certificates and now I am experiencing domain verification issues.

I have one certificate which has several SANs, but right now verification fails again and again. Sometimes for the first SAN, sometimes for the second or any other domain with the message: ‘DNS problem: query timed out looking up A for [braunlager-bikepark.de](http://braunlager-bikepark.de)’. I tried to debug and tried to resolve these domains from different places of the earth (using servers I have access to or DNS resolving websites), but found no problems.

Some of the SANs are:  
[harzer-bikeparx.de](http://harzer-bikeparx.de)  
[www.harzer-mountainbike-betten.de](http://www.harzer-mountainbike-betten.de)  
[www.family-harz.de](http://www.family-harz.de)  
[braunlager-bikepark.de](http://braunlager-bikepark.de)

---

<div class="post-metadata">

**Author:** ![actionm](https://avatars.discourse-cdn.com/v4/letter/a/f14d63/32.png) [@actionm](https://community.letsencrypt.org/u/actionm)\
**Post date:** [February 8, 2016, 9:54pm UTC](https://community.letsencrypt.org/t/dns-resolver-issues/10487/2 "2016-02-08T21:54:58Z")

</div>

I confirm, that I have the same problem.

FailedChallenges: Failed authorization procedure. XXXXXXXXXXXXXXXXXXXXXX (tls-sni-01): urn:acme:error:connection ::  
The server could not connect to the client to verify the domain ::  
DNS problem: query timed out looking up A for XXXXXXXXXXXXXXXXXXXXXX

Failed authorization procedure. XXXXXXXXXXXXXXXXXXXXXX (tls-sni-01): urn:acme:error:connection ::  
The server could not connect to the client to verify the domain ::  
DNS problem: query timed out looking up A for XXXXXXXXXXXXXXXXXXXXXX

---

<div class="post-metadata">

**Author:** ![morksmail](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/morksmail/32/5040_2.png) [@morksmail](https://community.letsencrypt.org/u/morksmail)\
**Post date:** [February 8, 2016, 10:00pm UTC](https://community.letsencrypt.org/t/dns-resolver-issues/10487/3 "2016-02-08T22:00:56Z")

</div>

Same here: DNS problem: query timed out looking up A for [www.XXXXXXX.com](http://www.XXXXXXX.com)’  
Everything resolves fine for me, but not so much on the other end of the process.

---

<div class="post-metadata">

**Author:** ![tradenet](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/tradenet/32/5042_2.png) [@tradenet](https://community.letsencrypt.org/u/tradenet)\
**Post date:** [February 8, 2016, 10:25pm UTC](https://community.letsencrypt.org/t/dns-resolver-issues/10487/4 "2016-02-08T22:25:35Z")

</div>

Seems to be some maintenance going on:  
[https://letsencrypt.status.io/](https://letsencrypt.status.io/)

Scroll down to the bottom. Says only 1 hr but maybe it’s still happening.

---

<div class="post-metadata">

**Author:** ![fingertrouble](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/fingertrouble/32/5044_2.png) [@fingertrouble](https://community.letsencrypt.org/u/fingertrouble)\
**Post date:** [February 8, 2016, 10:35pm UTC](https://community.letsencrypt.org/t/dns-resolver-issues/10487/5 "2016-02-08T22:35:34Z")

</div>

Odd. My domains weren’t going to expire til the 14th then I suddenly get this email:

Your certificate (or certificates) for the names listed below will expire in 0 days (on 09 Feb 16 18:30 +0000)

Hence the panic, when I try to renew them before tomorrow and I can’t because of Maintenance and then get DNS errors when trying to scramble to renew them.

It’s not really confidence building. I’m guessing they might have accidentally DOS-ed themselves with those emails? Some kind of glitch that moved soon to expire domains to expire the next day (or false warning)?

---

<div class="post-metadata">

**Author:** ![morksmail](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/morksmail/32/5040_2.png) [@morksmail](https://community.letsencrypt.org/u/morksmail)\
**Post date:** [February 9, 2016, 4:51am UTC](https://community.letsencrypt.org/t/dns-resolver-issues/10487/6 "2016-02-09T04:51:02Z")

</div>

I gave it the afternoon off and just came back to it. I was just able to get a cert with 100 domains. When I saw the DNS issue I was lucky to make it 5 domains into the list before it died.

Thanks to someone, somewhere for fixing something!

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [February 9, 2016, 6:51pm UTC](https://community.letsencrypt.org/t/dns-resolver-issues/10487/7 "2016-02-09T18:51:34Z")

</div>

Sorry for the issues. We deployed a change to our DNS configuration to mitigate timeouts people have been seeing with NetRegistry. Unfortunately, this caused a significant increase in timeouts for other registrars, and we rolled it back. Things should be back to normal. Please let us know if you see further problems of this sort.

---

<div class="post-metadata">

**Author:** ![com2](https://avatars.discourse-cdn.com/v4/letter/c/a6a055/32.png) [@com2](https://community.letsencrypt.org/u/com2)\
**Post date:** [March 22, 2016, 5:13pm UTC](https://community.letsencrypt.org/t/dns-resolver-issues/10487/8 "2016-03-22T17:13:50Z")

</div>

Question. The roll-back was a client side or (your) server side? I ask, because I use the hosting control panel LiveConfig where I see a similar status message: “DNS problem: query timed out looking up A for…”

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [March 22, 2016, 9:32pm UTC](https://community.letsencrypt.org/t/dns-resolver-issues/10487/9 "2016-03-22T21:32:51Z")

</div>

It was a server side issue. If you’re getting DNS timeouts today, they have some other cause. Maybe start a new thread and post your domain name?
