olespete
Member
Trust No One
- Joined:
- Jun 2024
- Posts:
- 270
- From:
- Unknown
This is EXACTLY why I run redundant DNS. Never trust a single registrar's nameservers. What could go wrong:
- Nameserver compromise (malicious zone edits)
- DDoS on provider infrastructure
- Configuration drift during "maintenance"
- Insider threat deleting zones
- BGP hijack of NS IPs
Set up secondary DNS with independent provider IMMEDIATELY. Also check your logs for unauthorized transfers—this could be precursor to hijacking!
fail2ban on your servers, obviously. But that won't help if the registrar itself is the attack surface.
airgapped, encrypted, faraday'd, still worried
MARIA3
Member
- Joined:
- Jul 2024
- Posts:
- 126
- From:
- Madrid, ES
I make test from Madrid and also cannot resolve. This is not local problem, is RackNerd problem.
I check their nameservers with online tool and both show timeout. Very strange because status page says all ok. I sent ticket yesterday too, no answer yet.
For temporary fix, you can change nameservers to Vultr or GreenCloudVPS if registrar allows. I did this with one domain last year when similar problem with other provider. Not ideal but make a server up again.
Regards 😊
siesta first, deploy later
moebig
Member
RAID is not backup
- Joined:
- Jul 2024
- Posts:
- 115
- From:
- Casablanca, Morocco
Wesh ana, same issue here with 3 domains on RackNerd. Le server حلو in theory but DNS is mort
Incha'allah they fix soon but I'm not waiting. Transferring to HostHatch tonight (ironic, same name as my broken domain lol) — https://hosthatch.com. Their NS responded in 12ms from my test.
RackNerd finally posted update 20 minutes ago: "degraded DNS performance in region" — region?? I test from Paris, Dubai, and Montreal, all dead. "degraded" is cute way to say "completely broken" I think.
Good luck all
RAID 1: because paranoia pays
olespete
Member
Trust No One
- Joined:
- Jun 2024
- Posts:
- 270
- From:
- Unknown
Set up secondary DNS with independent provider IMMEDIATELY
To be clear I meant third-party DNS hosting, not registrar DNS. Cloudflare, NS1, Amazon Route 53, whatever. Your registrar handles delegation, your DNS host handles resolution. Separate the blast radius.
Already seeing reports on Twitter that RackNerd's whois server is also timing out now. Not just resolution—their whole port 43 listener. That's a different subsystem entirely.
airgapped, encrypted, faraday'd, still worried