From: Alwyn Smith <alwyn§>
Date: Thu, 20 Nov 2003 17:24:20 +1000
Hi Anand,

I should have provided a clearer explanation. :)

Bind running in delegation-only mode will not resolve addresses where the
name servers for the domain in question are (ultimately) all in another TLD
and where the prime TLD registry does not support glue for nameservers in
another TLD.

In my example nameservers are in .au (,
but the nameservers for are in .com ( and
resolution fails at that point - no glue.

To ensure reliablility under the world according to delegation-only you need
at least one nameserver completely within the same TLD or you become
invisible to people who disagree with Verisign.

This is not specific to .au and is not finger pointing, simply an


Hi Alwyn,

I'm coming a bit late here and it would seem you've since resolved your
problem. However I'm not sure I understand what the original problem
was, could you elaborate futher?

> This one had me going for a while because the problem was further up the
> chain than I was looking.  Hopefully this info may help someone else with
> "inexplicable" dns failures on .au domains.
> would not resolve:
>       2554    IN      NS
>       2554    IN      NS

so, dig and dig would both

> 2554    IN      A
> 2554    IN      A

Were these glue records for or were they listed as NS in
the zone file?

>     2477    IN      NS
>     2477    IN      NS

Same question as above.

> If you operate bind in "delegation only" mode then lookups of .au domains
> with name servers _ultimately_ in "delegation only" domains will fail.

So this is a client problem (i.e. the admin of a zone has setup
delegation only) and there isn't much that a third party zone operator
can do about things?

Not sure I fully understand, and insight would be appreciated.


