is there a global DNS issue happening?
faa.gov
faa.gov
Successive queries using dig have given me:
- No answer but no error for initial A record query
- SERVFAIL for ANY record query
- Valid A record response for A record query, then no answer, then a response
- Query for ANY shows some DNSSEC related records, TXT, NS, but no A record
It's weird because I wouldn't think whatever caching my ISP is doing would refresh that fast. What is the evidence this is an attack vs. a misconfiguration?
Also, would an outage like this have any impact on US flights or flights in US airspace?
I'm guessing a lot of sites that had name-servers hosted in AS5089 might also have gone down too.
But as of 30 minutes ago, apparently it's back online.
All of the other NSes have been hard down, and 155.178.199.16 only seems to respond from some locations (broadly US works, International does not)
; <<>> DiG 9.11.5-P4-5.1+deb10u8-Debian <<>> +noedns faa.gov @155.178.199.16
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 28118
;; flags: qr aa rd; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
;; WARNING: recursion requested but not available
;; QUESTION SECTION:
;faa.gov. IN A
;; AUTHORITY SECTION:
faa.gov. 300 IN SOA faa-mc-igms.faa.gov. helpdesk.faa.gov. 172720 10800 1080 2419200 300
;; Query time: 558 msec
;; SERVER: 155.178.199.16#53(155.178.199.16)
;; WHEN: Tue Apr 04 02:47:54 UTC 2023
;; MSG SIZE rcvd: 82
but 155.178.199.16 seems to respond to www.faa.gov correctly: ;; QUESTION SECTION:
;www.faa.gov. IN A
;; ANSWER SECTION:
www.faa.gov. 600 IN CNAME www.faa.gov.edgekey.net.What we have observed so far is intermittent issues but no root cause or intent. Operator error / system failure look more likely.
If I had to guess randomly at a cause, I would speculate that all their nameservers besides 155.178.199.16 are behind a load balancer that uses checking for IN A faa.gov as a health check and someone deleted that record, so, all servers fell out of the load balancer.
50c says that their method of propagating new records relies on their DNS working so someone is having a fun night fixing that.
```
> dog -n 1.1.1.1 -t A faa.gov
[prints the A record]
> dog -n 8.8.8.8 -t A faa.gov
Server failure.
```