Tell HN: All .fj domains have gone offline
fiji.gov.fj
usp.ac.fj
etc.
http://www.iana.org/domains/root/db/fj.html
fiji.gov.fj
usp.ac.fj
etc.
http://www.iana.org/domains/root/db/fj.html
Google's DNS server at 8.8.8.8 is having problems.
Lookup using DNS server of sonic.net, which is a normal DNS server.
nslookup usp.ac.fj
Server: 127.0.0.53
Address: 127.0.0.53#53
Non-authoritative answer:
Name: usp.ac.fj
Address: 144.120.141.80
Lookup with Google DNS: nslookup
> server 8.8.8.8
Default server: 8.8.8.8
Address: 8.8.8.8#53
> usp.ac.fj
Server: 8.8.8.8
Address: 8.8.8.8#53
** server can't find usp.ac.fj: SERVFAIL
Checking example.com to make sure Google DNS server is live. > example.com
Server: 8.8.8.8
Address: 8.8.8.8#53
Non-authoritative answer:
Name: example.com
Address: 93.184.216.34
Name: example.com
Address: 2606:2800:220:1:248:1893:25c8:1946
Also fails with 1.1.1.1 DNS server.The Fiji DNS servers are unreachable, but you can get as far as a router at the University of the South Pacific. So the problem is local to there.
traceroute 144.120.146.1
traceroute to 144.120.146.1 (144.120.146.1), 30 hops max, 60 byte packets
...
8 AARNET-PTY.edge5.London1.Level3.net (217.163.113.74) 274.795 ms 274.476 ms 273.781 ms
9 xe-0-0-0.pe1.a.suv.aarnet.net.au (113.197.15.213) 312.534 ms 311.764 ms 311.766 ms
10 fastethernet0-0.aarnie.usp.ac.fj (202.158.204.194) 313.356 ms 312.176 ms 312.363 ms
11 * * *
12 * * *
[1] https://www.usp.ac.fj/Not up from within Fiji. All government websites (and email) are down. Banks, Universities, mobile money wallets, etc.
> server 144.120.141.80 Default server: 144.120.141.80 Address: 144.120.141.80#53 > usp.ac.fj Server: 144.120.141.80 Address: 144.120.141.80#53
* server can't find usp.ac.fj: SERVFAIL
This is due to an outage in the University of the South Pacific hosted dotcom.fj domain." [1][2]
[1] https://www.fijivillage.com/news/All-websites--apps-in-Fiji-...
[2] https://twitter.com/fijivillage/status/1501070675691278339
And 10 mins on anything I'm about to make changes to. That means if I accidentally make the wrong change, the 'blast radius' is minimized.
Obviously, when changing 24h down to 10 mins, keep a close eye on DNS server load, packet loss on links close to it, etc. If in doubt, raise and lower ttl's slowly.
Two are operated by gransy.com and one by PCH.net (which you should consider donating to and helping random country codes stay online: https://www.pch.net/about/donate).
"Google Public DNS is a validating, security-aware resolver. All responses from DNSSEC signed zones are validated unless clients explicitly set the CD flag in DNS requests to disable the validation."
couldn't get address for 'ns4.fj': not found
couldn't get address for 'ns5.fj': not found
couldn't get address for 'ns2.fj': not found
couldn't get address for 'ns1.fj': not found
couldn't get address for 'ns3.fj': not found
dig: couldn't get address for 'ns4.fj': no moreI'm in England, for what that's worth.
Consider AQ, TW, GG, SJ, EH, HK and many others.
AQ is controversial to countries who want to exploit Antarctica's natural resources.
TW is controversial to China.
GG is controversial where it's used for tax evasion etc.
EH to Morocco, HK to the UK/China.
Also there were some comments from the owner at the time that I thought were pretty unprofessional about it, too.
https://www.theregister.com/2010/05/12/germany_top_level_dom...
There is one very recent exception however, the russian plans to partly separate from the internet shortly (especially regarding DNS) could well be an issue.
Registries range in resources from "highly experienced billion-dollar organizations", to literally "we have a guy who updates the zone file in notepad", and they range in legal environment from, "functional democratic state with well-established judiciary" to "our government was violently overthrown this week".
Whether or not the problem is negligible depends on your particular use-case. For some, it might be a good choice, for others, it might not be.