[GH-ISSUE #662] DNS Verification Failing #473

Closed
opened 2026-03-01 17:47:39 +03:00 by kerem · 4 comments
Owner

Originally created by @nickrupert7 on GitHub (Jul 20, 2024).
Original GitHub issue: https://github.com/anonaddy/anonaddy/issues/662

Hello, I have been using anonaddy/addy.io for over a year and a half now. Until recently, it has worked just fine, but now, I am suddenly receiving DNS verification errors on my custom domain with the following error messages:

CNAME dk1._domainkey record not found. This could be due to DNS caching, please try again later.

CNAME dk2._domainkey record not found. This could be due to DNS caching, please try again later.

The past few days, it's been on and off - One minute it will verify, then that evening, I'll get the email that verification is failing again, and when I manually recheck, it just keeps failing.

I did recently migrate my domain name registration and DNS to AWS Route 53, but this was over a week ago, and I can confirm that all of the correct records ARE in my Hosted Zone. 3rd party DNS query tools also always return the correct records. The TTL on the relevant records in both the old and new DNS were 300s (5 mins), so it really shouldn't be a caching issue several days later like this.

This same issue was also referenced in https://github.com/anonaddy/anonaddy/issues/491, but no solution was ever given because it seemingly resolved itself.

Originally created by @nickrupert7 on GitHub (Jul 20, 2024). Original GitHub issue: https://github.com/anonaddy/anonaddy/issues/662 Hello, I have been using anonaddy/addy.io for over a year and a half now. Until recently, it has worked just fine, but now, I am suddenly receiving DNS verification errors on my custom domain with the following error messages: `CNAME dk1._domainkey record not found. This could be due to DNS caching, please try again later.` `CNAME dk2._domainkey record not found. This could be due to DNS caching, please try again later.` The past few days, it's been on and off - One minute it will verify, then that evening, I'll get the email that verification is failing again, and when I manually recheck, it just keeps failing. I did recently migrate my domain name registration and DNS to AWS Route 53, but this was over a week ago, and I can confirm that all of the correct records ARE in my Hosted Zone. 3rd party DNS query tools also always return the correct records. The TTL on the relevant records in both the old and new DNS were 300s (5 mins), so it really shouldn't be a caching issue several days later like this. This same issue was also referenced in https://github.com/anonaddy/anonaddy/issues/491, but no solution was ever given because it seemingly resolved itself.
kerem closed this issue 2026-03-01 17:47:39 +03:00
Author
Owner

@willbrowningme commented on GitHub (Jul 22, 2024):

Please could you send me an email with details of your domain so that I can have a look into this?

<!-- gh-comment-id:2242458031 --> @willbrowningme commented on GitHub (Jul 22, 2024): Please could you [send me an email](https://addy.io/contact/) with details of your domain so that I can have a look into this?
Author
Owner

@nickrupert7 commented on GitHub (Jul 22, 2024):

Email sent. Thanks!

<!-- gh-comment-id:2243878658 --> @nickrupert7 commented on GitHub (Jul 22, 2024): Email sent. Thanks!
Author
Owner

@willbrowningme commented on GitHub (Jul 26, 2024):

It seems this issue was caused by an incorrect DNSSEC configuration after recently changing DNS Providers.

<!-- gh-comment-id:2252770741 --> @willbrowningme commented on GitHub (Jul 26, 2024): It seems this issue was caused by an incorrect DNSSEC configuration after recently changing DNS Providers.
Author
Owner

@nickrupert7 commented on GitHub (Jul 28, 2024):

Confirming for future reference: Enabling DNSSEC on my domain did appear to resolve the issue. If you find yourself in the same boat as me, please try enabling DNSSEC and everything should validate correctly!

Thank you @willbrowningme !

<!-- gh-comment-id:2254544222 --> @nickrupert7 commented on GitHub (Jul 28, 2024): Confirming for future reference: Enabling DNSSEC on my domain did appear to resolve the issue. If you find yourself in the same boat as me, please try enabling DNSSEC and everything should validate correctly! Thank you @willbrowningme !
Sign in to join this conversation.
No labels
bug
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/anonaddy#473
No description provided.