🌐

DNS Error

DNS Error: SERVFAIL

The DNS server encountered an internal error and could not process the query — distinct from NXDOMAIN, which is a definitive "doesn't exist" answer.

What This Error Means

SERVFAIL means the DNS server itself hit a problem while trying to resolve the query — this could be at the resolver level (your configured DNS server is misconfigured or overloaded) or at the authoritative nameserver level (the domain's own DNS servers are broken or misconfigured, e.g. a broken DNSSEC signature).

Why It Occurs

Common causes include the domain's authoritative nameservers being misconfigured or unreachable, a broken DNSSEC configuration causing validation failures, or the resolver you're querying being overloaded or having its own internal issue.

Symptoms

  • ⚠ `dig`/`nslookup` explicitly show "SERVFAIL" in the status line
  • ⚠ Intermittent — may work against one resolver but fail against another

Common Causes

  • • The domain's authoritative nameservers are misconfigured, unreachable, or returning malformed responses
  • • Broken DNSSEC signatures causing validating resolvers to reject the response
  • • The specific DNS resolver being queried is overloaded or has an internal fault

How to Fix It

  1. Test against a different public resolver to isolate whether it's resolver-specific: `dig example.com @1.1.1.1` vs `dig example.com @8.8.8.8`
  2. If it fails against multiple independent resolvers, the problem is with the domain's own authoritative nameservers — check them directly: `dig example.com @ns1.the-domains-nameserver.com`
  3. If DNSSEC is enabled, check DNSSEC validation status: `dig +dnssec example.com` and check for signature/validation errors
  4. If you control the domain's DNS, verify the nameserver records at your registrar match the ones actually hosting the zone, and that the authoritative servers are actually reachable and serving the zone correctly
CommandPurpose
dig example.com @1.1.1.1Test against a specific resolver to isolate resolver-side vs. authoritative-side issues
dig +dnssec example.comCheck for DNSSEC validation failures
Advertisement

Verification

  • ✓ Queries against multiple resolvers all return a valid answer instead of SERVFAIL

Prevention

  • → Monitor authoritative nameserver health independently of the main website/service monitoring
  • → Test DNSSEC changes carefully in a non-production zone before applying to a live domain, since misconfigured DNSSEC is a common self-inflicted SERVFAIL cause

Related