RFC 2181 10.3 - compliance check needed does not (currently) resolve if you use BIND nameservers. This is because it violates the RFC by using NS records that point at CNAMEs. This was an absolute smeg to diagnose. Squish dnscheck V2 doesn't see it. Dnscheck V1 *does* highlight it (but doesn't say it's actually bad). Can detection for this really really nasty SERVFAIL thing get added to ...more »

