Intermittent CAA SERVFAILs Across Two DNS Providers

I don't see the CNAME...

Since it's on the root record it's flattened by Cloudflare and returned as an A record. My point mainly there was the more complex delegation going on for that domain is sort of invisible to the end-user (Let's Encrypt)

It uses Cloudflare CDN?

Name:      autotrader.co.uk
Addresses: 2606:4700::6810:e650
           2606:4700::6810:e550
           104.16.229.80
           104.16.230.80

If so, that's a bit different than the other FQDN.

1 Like

If you look at www.autotrader.co.uk as an example it CNAME's to prod.at2.p.autotrader.co.uk..

That then has some subdomain delegation on at2.p.autotrader.co.uk, somewhat similar to preprod.k8.atcloud.io. autotrader.co.uk is configured identically as www.autotrader.co.uk

OK but both names had the same problem:

1 Like

OK but both names had the same problem:

Yep :+1:

I might open up a support ticket with Cloudflare too alongside this thread to see if they can offer any advice, or have any observations from their internal tooling that might help to figure this out.
I'll also look at making the change to preprod.k8.atcloud.io to delegate differently, but might be later on in the week before I'm able to make that change

2 Likes

The two authoritative nameservers resolve to 12 IPs (six IPv6 and six IPv4):

Name:      ernest.ns.cloudflare.com
Addresses: 2803:f800:50::6ca2:c1a4
           2a06:98c1:50::ac40:21a4
           2606:4700:58::adf5:3ba4
           173.245.59.164
           108.162.193.164
           172.64.33.164

Name:      jessica.ns.cloudflare.com
Addresses: 2606:4700:50::adf5:3aab
           2803:f800:50::6ca2:c0ab
           2a06:98c1:50::ac40:20ab
           172.64.32.171
           173.245.58.171
           108.162.192.171

I've checked them all via TCP and UDP for CAA records of both FQDNs and can't spot any malfunction
:frowning:

1 Like

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.