Error Reference › SSL / DNS
SSL / DNS

DNS server failure / SERVFAIL

The DNS resolver itself failed to answer (not a missing record — a resolver problem).

What it looks like

dig example.com
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 3310

What does "DNS server failure / SERVFAIL" mean?

Returned when the resolver could not produce an answer at all — unlike NXDOMAIN, it is not saying the name is missing. Common causes are a broken DNSSEC signature, unreachable authoritative nameservers, or a faulty local resolver.

What causes "DNS server failure / SERVFAIL"?

  • The configured DNS server is down/unreachable.
  • A broken DNSSEC chain.
  • Bad /etc/resolv.conf or network DNS settings.

How do I confirm the cause?

  1. Try other resolvers (dig example.com @1.1.1.1 and @8.8.8.8). If one works and yours fails, the problem is your resolver.
  2. Run dig example.com +cd to disable DNSSEC checking — if that works, the domain’s DNSSEC is broken.
  3. Query the domain’s own nameservers directly (dig @ns1.provider.example example.com) to see whether they answer.
  4. Run the domain through an online DNSSEC analyser, which shows exactly where the chain of signatures breaks.

How do I fix "DNS server failure / SERVFAIL"?

  • Switch to a known-good resolver (1.1.1.1 / 8.8.8.8).
  • Check DNSSEC if it's enabled.
  • Verify the machine's DNS configuration and connectivity.

How do I stop it happening again?

  • When moving a DNSSEC-signed domain between providers, remove or update the DS record at the registrar as part of the move.
  • Use at least two authoritative nameservers on separate networks.
Got a different error? Paste it into the Explain This Error tool → Identifies the family and the fix — runs locally, nothing uploaded.

Related errors