SERVFAIL for www.schnaeppo.de

I noticed that 1.1.1.1 and 1.0.0.1 don’t resolve the domain www.schnaeppo.de but return SERVFAIL instead when looking up this domain.

Here’s the link to the output of the diagnostic tool:

cloudflare-dns.com

Here’s useful output from a linux machine in my network:

dig www.schnaeppo.de @1.1.1.1

; <<>> DiG 9.16.1-Ubuntu <<>> www.schnaeppo.de @1.1.1.1
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 58455
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1452
;; QUESTION SECTION:
;www.schnaeppo.de.		IN	A

;; Query time: 7 msec
;; SERVER: 1.1.1.1#53(1.1.1.1)
;; WHEN: Fr Jun 12 19:53:21 CEST 2020
;; MSG SIZE  rcvd: 45

dig www.schnaeppo.de @1.0.0.1

; <<>> DiG 9.16.1-Ubuntu <<>> www.schnaeppo.de @1.0.0.1
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 51905
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1452
;; QUESTION SECTION:
;www.schnaeppo.de.		IN	A

;; Query time: 2119 msec
;; SERVER: 1.0.0.1#53(1.0.0.1)
;; WHEN: Fr Jun 12 19:53:52 CEST 2020
;; MSG SIZE  rcvd: 45

dig www.schnaeppo.de @8.8.8.8

; <<>> DiG 9.16.1-Ubuntu <<>> www.schnaeppo.de @8.8.8.8
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 13178
;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;www.schnaeppo.de.		IN	A

;; ANSWER SECTION:
www.schnaeppo.de.	599	IN	CNAME	d1kkjapry09zec.cloudfront.net.
d1kkjapry09zec.cloudfront.net. 59 IN	A	52.222.174.228
d1kkjapry09zec.cloudfront.net. 59 IN	A	52.222.174.91
d1kkjapry09zec.cloudfront.net. 59 IN	A	52.222.174.227
d1kkjapry09zec.cloudfront.net. 59 IN	A	52.222.174.55

;; Query time: 27 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Fr Jun 12 19:54:09 CEST 2020
;; MSG SIZE  rcvd: 152

dig +short CHAOS TXT id.server @1.1.1.1
"FRA"

dig +short CHAOS TXT id.server @1.0.0.1
"FRA"

And here’s the link to DNSViz:
https://dnsviz.net/d/www.schnaeppo.de/dnssec/

A basic dnsviz shows it might be related to a configuration issue with their DNS:

https://dnsviz.net/d/www.schnaeppo.de/dnssec/

cloudfront.net to d1kkjapry09zec.cloudfront.net: The server(s) for the parent zone (cloudfront.net) responded with a referral instead of answering authoritatively for the DS RR type.