I’m having a weird DNS issue. I’ve made no changes to my firewall and nothing has changed (so far as I know) at my domain registrar but when I try to renew the TLS certificates I get DNS errors for two of my three domains. All are registered with the same company (LCN.com). When I run a DNS check at
It says no authoritative DNS found!! According to MiaB’s status page all the DNS settings are correct.
✓ Nameservers are set correctly at registrar. [ns1.box.gideon-it.com; ns2.box.gideon-it.com]
✓ Domain’s email is directed to this domain. [gideon-it.co.uk ↦ 10 box.gideon-it.com]
MTA-STS policy is missing: STSFetchResult.NONE
✓ Postmaster contact address exists as a mail alias. [postmaster@gideon-it.co.uk ↦ ptyler@gideon-it.co.uk]
✓ Domain is not blacklisted by dbl.spamhaus.org.
✓ Domain resolves to this box’s IP address. [gideon-it.co.uk ↦ 81.174.152.174]
✓ TLS (SSL) certificate is signed & valid. The certificate expires in 89 days on 2024-08-20.
? This domain’s DNSSEC DS record is not set. The DS record is optional. The DS record activates DNSSEC. See below for instructions.
show more
✓ www.gideon-it.co.uk: Domain resolves to this box’s IP address. [www.gideon-it.co.uk ↦ 81.174.152.174]
✓ www.gideon-it.co.uk: TLS (SSL) certificate is signed & valid. The certificate expires in 89 days on 2024-08-20.
✓ autoconfig.gideon-it.co.uk: Domain resolves to this box’s IP address. [autoconfig.gideon-it.co.uk ↦ 81.174.152.174]
✓ autoconfig.gideon-it.co.uk: TLS (SSL) certificate is signed & valid. The certificate expires in 89 days on 2024-08-20.
✓ autodiscover.gideon-it.co.uk: Domain resolves to this box’s IP address. [autodiscover.gideon-it.co.uk ↦ 81.174.152.174]
✓ autodiscover.gideon-it.co.uk: TLS (SSL) certificate is signed & valid. The certificate expires in 89 days on 2024-08-20.
The domain philipalantyler.co.uk sometimes comes back OK with authoritative DNS and sometimes doesn’t. The primary domain gideon-it.com is the same, sometimes it works, sometimes it doesn’t.
I’ve got 6 days or so left to renew the TLS certificates.
Is it worth rerunning the MiaB setup? Would this fix it? I’ve already tried that once when only the philipalantyler.co.uk domain renewed and it hasn’t helped.
According to ShieldsUp! port 53 is open on my firewall.
https://www.grc.com/x/ne.dll?rh1dkyd2
Any suggestions appreciated, especially suggestions that fix it!