Re: Cloudflare DNS contact?
Steve Sullivan via NANOG <[email protected]>
| Newsgroups | gmane.org.operators.nanog |
|---|---|
| Organization | DNS-OARC |
| Message-ID | <[email protected]> |
Hey Mark, Steve at DNS-OARC reaching out. I sent a note to the OP recommending she hit the OARC chat platform and mail list. Cloudflare DNS is actually pretty active in the DNS-OARC Member and at-large Community. Might want send these operational DNS questions to the dns-operations mailing list and to https://chat.dns-oarc.net. I try too when i see them, but I cannot read all the nanog mails. I hope to see you at a workshop soon. Kind regards, Steve Sullivan Membership Coordinator OARC Mattermost Chat: @stevos https://linktr.ee/dnsoarc On 4/6/2026 9:49 PM, marka via NANOG wrote: > > >> On 7 Apr 2026, at 12:08, Betsy Schwartz via NANOG<[email protected]> wrote: >> >> We're getting reports of users trying to log in or request 2FA emails from >> Cloudflare sites (ex: California DMV) but seeing errors that our well.com >> domain isn't recognized as valid. Well.com has been around since 1993 and >> our primary DNS hasn't changed since perhaps 2012. . Excerpts appended for >> reference. >> >> I strongly suspect these errors are related to a Cloudflare security check >> for valid email domains. Hoping someone here can validate or disprove >> this. If it's a Cloudflare issue, any contacts here? >> >> When I poke at an open cloudflare DNS server and look up the A for well.com >> I get a disturbing error: : >> server can't find well.com.well.sf.ca.us: >> >> well.sf.ca.us is an antique (but valid) A record in the sf.ca.us zone >> and has no business appearing here. Did something drop a period or CRLF >> on a list somewhere? > Nslookup is NOT a good diagnostic tool. Here it presumably tried well.com > then tried well.com.well.sf.ca.us when the first query failed as you have > well.sf.ca.us in the search list. This is one of the reasons it is not a > good diagnostic tool. Also different versions of nslookup move onto to > applying the next name in the search list differently. The only SAFE? way > to do search lists is to ONLY move to the next name on NXDOMAIN (Name Error). > Lots of search list implementations move to the next name in the search list > on SERVFAIL (you can get data from the wrong name used), NOERROR NODATA (you > end up talking to different domains as IPv4 and IPv6 addresses appear/disappear). > > I would suggest that you use a diagnostic tool like 'dig' which doesn’t do search > lists unless explicitly requested. > > Additionally if you want help, show everything you are doing. People then have > a better chance of find errors in your testing methodology. > >> When I query AWS and Google DNS servers, our DNS looks correct and >> unchanged >> Thank you very much for any pointers! >> >> Betsy >> >> -- >> Correct info: >>> set type=any >>> well.com >> Server: 8.8.8.8 >> Address: 8.8.8.8#53 >> Non-authoritative answer: >> Name: well.com >> Address: 23.22.72.90 >> well.com nameserver = ns-1783.awsdns-30.co.uk. >> well.com nameserver = ns-1103.awsdns-09.org. >> well.com nameserver = ns-805.awsdns-36.net. >> well.com nameserver = ns-459.awsdns-57.com. >> well.com >> origin = ns-1103.awsdns-09.org >> mail addr = awsdns-hostmaster.amazon.com >> <snip> >> well.com mail exchanger = 15 xmx.well.com. >> <snip> >> -- >> whois well.com >> [Querying whois.verisign-grs.com] >> Domain Name: WELL.COM >> Registry Domain ID: 4562093_DOMAIN_COM-VRSN >> Registrar WHOIS Server: whois.enom.com >> Registrar URL:http://www.enomdomains.com >> Updated Date: 2020-01-24T18:46:10Z >> Creation Date: 1993-01-25T05:00:00Z >> Registry Expiry Date: 2029-01-26T05:00:00Z >> <snip> >> Name Server: NS-1103.AWSDNS-09.ORG >> Name Server: NS-1783.AWSDNS-30.CO.UK >> Name Server: NS-459.AWSDNS-57.COM >> Name Server: NS-805.AWSDNS-36.NET >> <snip> >> _______________________________________________ >> NANOG mailing list >> https://lists.nanog.org/archives/list/[email protected]/message/6BU667JNHNF6XEW2G2MAVGZ5G5YCHREA/ _______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/[email protected]/message/DCLCRZ2QZ7ZERRSJW2TXPKQ22FISV6MJ/
OpenPGP_signature.asc
(application/pgp-signature, 840 B)
-----BEGIN PGP SIGNATURE----- wsF5BAABCAAjFiEErRWMi4SbfLaTNltuN9GxLPRN0IsFAmnVKzQFAwAAAAAACgkQN9GxLPRN0IvI cBAAnar229HycjS0Yr8PZ//RkezXUVefnJIUd4H9kjHnLrEm9pFig4s5FIE/9nhkDGDpH0WcCp3+ ef3HH+YaSiyaN7fhUerWA3In4v/1SikYR9n/NM8Rj0aNIdarPusBevkbKOwBW1R7Y87dB/wVJvkv PR5MX+ETrbc9qAJZol29yY4BAuoSIFXhHKllhwJ7BOkNlSYKzywpw73oSvu1E2OVqxXCiIdRP34u Q5ejGrd6dAc6tCun3S3+UcufAwWkugWkA80RvvmrU2otw9FZdVqqQwL8j2WDCoW+G/r2ltBnx/Ls lhe75U7HQuF9iOUACYBnim0Fkr/y4cfl5pC/EkRT7DW5Q/TS7PRISQDfqnghp71QOMGa1OZJoMe1 StHXpymHjbPrCaE72vyooXLxVmTTPPA7XrXhmefNMHZbjIr1BUHuHeBKzcM2E6CBobtUs2llfkiS Pl17MHQgP5eOwbXV1oORiiqQiK/9qp/CquxpVt4a896O0AHrSKLU1gAcXIrDL0rAZgtUd8wgO/yw X9WB6p61iywvypxwM+kGj0ArRZ9b3ZZl0b74o2JaYS88bOeafiynipeKpjh4MDXb8ec6mn/MC10D d27UXiRVVmhl4xWIqi9xeZK2AdMco5BzoKxg3Ff1DD+90Y7B9EP2cpESTeDQspaFTNXZCMMSZRdi 4P4= =GDfu -----END PGP SIGNATURE-----