Error Reference › SSL / DNS
SSL / DNS
DNS server failure / SERVFAIL
The DNS resolver itself failed to answer (not a missing record — a resolver problem).
What it looks like
dig example.com
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 3310
What does "DNS server failure / SERVFAIL" mean?
Returned when the resolver could not produce an answer at all — unlike NXDOMAIN, it is not saying the name is missing. Common causes are a broken DNSSEC signature, unreachable authoritative nameservers, or a faulty local resolver.
What causes "DNS server failure / SERVFAIL"?
- The configured DNS server is down/unreachable.
- A broken DNSSEC chain.
- Bad /etc/resolv.conf or network DNS settings.
How do I confirm the cause?
- Try other resolvers (dig example.com @1.1.1.1 and @8.8.8.8). If one works and yours fails, the problem is your resolver.
- Run dig example.com +cd to disable DNSSEC checking — if that works, the domain’s DNSSEC is broken.
- Query the domain’s own nameservers directly (dig @ns1.provider.example example.com) to see whether they answer.
- Run the domain through an online DNSSEC analyser, which shows exactly where the chain of signatures breaks.
How do I fix "DNS server failure / SERVFAIL"?
- Switch to a known-good resolver (1.1.1.1 / 8.8.8.8).
- Check DNSSEC if it's enabled.
- Verify the machine's DNS configuration and connectivity.
How do I stop it happening again?
- When moving a DNSSEC-signed domain between providers, remove or update the DS record at the registrar as part of the move.
- Use at least two authoritative nameservers on separate networks.