Kenic.or.ke unresolvable on 1.1.1.1


#1

Been having issues with this domain when on the MBA/JNB clusters. Tried with an OVH VM hitting the FRA cluster and it goes through ok.

$ dig @1.1.1.1 kenic.or.ke

; <<>> DiG 9.10.6 <<>> @1.1.1.1 kenic.or.ke
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 46677
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1452
;; QUESTION SECTION:
;kenic.or.ke.                   IN      A

;; Query time: 4271 msec
;; SERVER: 1.1.1.1#53(1.1.1.1)
;; WHEN: Tue Feb 12 16:09:21 EAT 2019
;; MSG SIZE  rcvd: 40

$ dig @1.0.0.1 kenic.or.ke

; <<>> DiG 9.10.6 <<>> @1.0.0.1 kenic.or.ke
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 19630
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1452
;; QUESTION SECTION:
;kenic.or.ke.                   IN      A

;; Query time: 1039 msec
;; SERVER: 1.0.0.1#53(1.0.0.1)
;; WHEN: Tue Feb 12 16:09:36 EAT 2019
;; MSG SIZE  rcvd: 40

$ dig @8.8.8.8 kenic.or.ke

; <<>> DiG 9.10.6 <<>> @8.8.8.8 kenic.or.ke
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 11834
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;kenic.or.ke.                   IN      A

;; ANSWER SECTION:
kenic.or.ke.            275     IN      A       198.32.67.18

;; Query time: 238 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Tue Feb 12 16:09:47 EAT 2019
;; MSG SIZE  rcvd: 56

$ dig +short CHAOS TXT id.server @1.1.1.1
"JNB"
$ dig +short CHAOS TXT id.server @1.0.0.1
"JNB"

#2

That domain’s DNS servers have a lot of errors: http://dnsviz.net/d/kenic.or.ke/dnssec/