Re: Cloudflare DNS contact?

Steve Sullivan via NANOG <[email protected]>
Newsgroups gmane.org.operators.nanog
Organization DNS-OARC
Message-ID <[email protected]>
Hey Mark,

Steve at DNS-OARC reaching out. I sent a note to the OP recommending she 
hit the OARC chat platform and mail list.

Cloudflare DNS is actually pretty active in the DNS-OARC Member and 
at-large Community. Might want send these operational DNS questions to 
the dns-operations mailing list and to https://chat.dns-oarc.net.

I try too when i see them, but I cannot read all the nanog mails.

I hope to see you at a workshop soon.

Kind regards,

Steve Sullivan
Membership Coordinator
OARC Mattermost Chat: @stevos
https://linktr.ee/dnsoarc

On 4/6/2026 9:49 PM, marka via NANOG wrote:
>   
>
>> On 7 Apr 2026, at 12:08, Betsy Schwartz via NANOG<[email protected]> wrote:
>>
>> We're getting reports of users trying to log in or request 2FA emails from
>> Cloudflare sites (ex: California DMV) but seeing   errors that our well.com
>> domain isn't recognized as valid.  Well.com  has been around since 1993 and
>> our primary DNS hasn't changed since perhaps 2012. . Excerpts appended for
>> reference.
>>
>> I strongly suspect these errors are related to a Cloudflare security check
>> for valid email domains. Hoping someone here can validate or disprove
>> this.  If it's a Cloudflare issue, any contacts here?
>>
>> When I poke at an open cloudflare DNS server and  look up the A for well.com
>> I get a disturbing error: :
>>          server can't find well.com.well.sf.ca.us:
>>
>> well.sf.ca.us is an antique  (but valid) A  record in  the sf.ca.us zone
>> and has no business appearing here.  Did something drop a period or  CRLF
>> on a list somewhere?
> Nslookup is NOT a good diagnostic tool.  Here it presumably tried well.com
> then tried well.com.well.sf.ca.us when the first query failed as you have
> well.sf.ca.us in the search list.  This is one of the reasons it is not a
> good diagnostic tool.  Also different versions of nslookup move onto to
> applying the next name in the search list differently.  The only SAFE? way
> to do search lists is to ONLY move to the next name on NXDOMAIN (Name Error).
> Lots of search list implementations move to the next name in the search list
> on SERVFAIL (you can get data from the wrong name used),  NOERROR NODATA (you
> end up talking to different domains as IPv4 and IPv6 addresses appear/disappear).
>
> I would suggest that you use a diagnostic tool like 'dig' which doesn’t do search
> lists unless explicitly requested.
>
> Additionally if you want help, show everything you are doing.  People then have
> a better chance of find errors in your testing methodology.
>
>> When I query AWS and Google DNS servers,  our DNS  looks correct and
>> unchanged
>> Thank you very much for any pointers!
>>
>> Betsy
>>
>> --
>> Correct info:
>>> set type=any
>>> well.com
>> Server:         8.8.8.8
>> Address:        8.8.8.8#53
>> Non-authoritative answer:
>> Name:   well.com
>> Address: 23.22.72.90
>> well.com        nameserver = ns-1783.awsdns-30.co.uk.
>> well.com        nameserver = ns-1103.awsdns-09.org.
>> well.com        nameserver = ns-805.awsdns-36.net.
>> well.com        nameserver = ns-459.awsdns-57.com.
>> well.com
>>         origin = ns-1103.awsdns-09.org
>>         mail addr = awsdns-hostmaster.amazon.com
>> <snip>
>> well.com        mail exchanger = 15 xmx.well.com.
>> <snip>
>> --
>> whois well.com
>> [Querying whois.verisign-grs.com]
>>    Domain Name: WELL.COM
>>    Registry Domain ID: 4562093_DOMAIN_COM-VRSN
>>    Registrar WHOIS Server: whois.enom.com
>>    Registrar URL:http://www.enomdomains.com
>>    Updated Date: 2020-01-24T18:46:10Z
>>    Creation Date: 1993-01-25T05:00:00Z
>>    Registry Expiry Date: 2029-01-26T05:00:00Z
>>   <snip>
>>    Name Server: NS-1103.AWSDNS-09.ORG
>>    Name Server: NS-1783.AWSDNS-30.CO.UK
>>    Name Server: NS-459.AWSDNS-57.COM
>>    Name Server: NS-805.AWSDNS-36.NET
>> <snip>
>> _______________________________________________
>> NANOG mailing list
>> https://lists.nanog.org/archives/list/[email protected]/message/6BU667JNHNF6XEW2G2MAVGZ5G5YCHREA/

_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/[email protected]/message/DCLCRZ2QZ7ZERRSJW2TXPKQ22FISV6MJ/
OpenPGP_signature.asc (application/pgp-signature, 840 B)
-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEErRWMi4SbfLaTNltuN9GxLPRN0IsFAmnVKzQFAwAAAAAACgkQN9GxLPRN0IvI
cBAAnar229HycjS0Yr8PZ//RkezXUVefnJIUd4H9kjHnLrEm9pFig4s5FIE/9nhkDGDpH0WcCp3+
ef3HH+YaSiyaN7fhUerWA3In4v/1SikYR9n/NM8Rj0aNIdarPusBevkbKOwBW1R7Y87dB/wVJvkv
PR5MX+ETrbc9qAJZol29yY4BAuoSIFXhHKllhwJ7BOkNlSYKzywpw73oSvu1E2OVqxXCiIdRP34u
Q5ejGrd6dAc6tCun3S3+UcufAwWkugWkA80RvvmrU2otw9FZdVqqQwL8j2WDCoW+G/r2ltBnx/Ls
lhe75U7HQuF9iOUACYBnim0Fkr/y4cfl5pC/EkRT7DW5Q/TS7PRISQDfqnghp71QOMGa1OZJoMe1
StHXpymHjbPrCaE72vyooXLxVmTTPPA7XrXhmefNMHZbjIr1BUHuHeBKzcM2E6CBobtUs2llfkiS
Pl17MHQgP5eOwbXV1oORiiqQiK/9qp/CquxpVt4a896O0AHrSKLU1gAcXIrDL0rAZgtUd8wgO/yw
X9WB6p61iywvypxwM+kGj0ArRZ9b3ZZl0b74o2JaYS88bOeafiynipeKpjh4MDXb8ec6mn/MC10D
d27UXiRVVmhl4xWIqi9xeZK2AdMco5BzoKxg3Ff1DD+90Y7B9EP2cpESTeDQspaFTNXZCMMSZRdi
4P4=
=GDfu
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.