Social Icons

Pages

Showing posts with label Custom Domains Diagnoses. Show all posts
Showing posts with label Custom Domains Diagnoses. Show all posts

Monday, 14 October 2013

Why Do We Need Four DNS Servers?

Occasionally, we see a perplexed blog owner asking a popular question about custom domain setup.
Does my domain really need four servers?
Some even seem to think that newer domains, with less readers, can get by with less - even one - servers.

Won't one server do - at least, for newer blogs? Theoretically, yes. But not one server is going to be 100% reliable, or last forever. Every computer ever made, like every human born, will die, one day.

Your blog (and your domain) depends upon DNS, to resolve its address. Address resolution is an essential part of helping your computer connect with the computer where your blog is stored.

If you specify just one server for your domain, and that one server goes down, your domain will be out of service - to the people depending upon that one server.

The named DNS server "ghs.google.com" is a redundant server array.
www.mydomain.com. 3600 IN CNAME ghs.google.com.

We use a "CNAME" to reference "ghs.google.com" - and we can't always use a "CNAME". Most registrars will not let you use a "CNAME" to resolve the domain root.

Google provides the 4 x "A" addressed server set, to resolve the domain root - when you wish to simply redirect the domain root to one of the aliases. Most domain owners will redirect the root to the "www" alias - though you are allowed to redirect to any one alias, at your discretion.

Google provides four mutually redundant individual servers, each responding to a specific IP address, for custom domain clients to access in a round robin sequence.

If any one server in the array of four becomes overloaded or goes out of service, and doesn't respond to a DNS query, the DNS resolver, on any client computer, will try the next server defined - if there is another server provided. If your domain provides just one server to resolve its address, and that one server goes down, your domain goes out of service. Your readers will see, yet again
404 Server Not Found
But wait - - there's more. Since Google provides four servers, and only one is out of service, they won't regard that as a major emergency. They still have three servers online - and nobody is losing sleep. Except, of course, you.

Google will repair or replace their one down server, when it is convenient to them. Maybe that will be next week, when their DNS server technician gets back from vacation.

Is that not convenient to you? Sorry.

With an asymmetrical configuration, you may not publish to the domain root. Your only valid choice is to publish to "www.mydomain.com", and select "Redirect mydomain.com to www.mydomain.com". If you publish to "mydomain.com", you will eventually see
Another blog is already hosted at this address.
or
Blogs may not be hosted at naked domains.

If you want to publish your blog to a custom domain using an ASymmetrical configuration, always publish to "www.mydomain.com", not to "mydomain.com". If you want to publish to "mydomain.com", you'll have to use a Symmetrical DNS configuration, and risk losing services hosted by your registrar. If you go with the first option, you will need all 4 servers - if you want a reliable and supported custom domain.

If your registrar or hosting service does not support 4 x "A" DNS addresses setup, you may want to use a (free) third party DNS host. Now, here's hoping that your registrar allows easy configuration of third party DNS service.

>> Top

Friday, 1 March 2013

eNom Hosted Custom Domains Again Showing Intermittent Connectivity Issues

This week, we have a few reports in Blogger Help Forum: Something Is Broken, about active and mature domains, suddenly stopped working.
I have used my domain with no problems, since last year. Today, it suddenly stopped working, and the browser reports
Oops! Google Chrome could not find www.mydomain.com.
I asked my friends about my domain - and they tell me that my blog is inaccessible to them, also. I didn't change any settings - and it was fine, until last night.

As we reported last year, the Google partner registrar eNom occasionally has a problem with their DNS server complement. Right now, one of their DNS servers appears consistently bad.

Using a comprehensive Dig tool, we can observe a given domain, and compare the DNS addresses being served by all authoritative name servers for a given domain, in a single transaction.

Here's a hypothetical example, of what we're seeing right now, for several eNom hosted domains.

mycustomdomain.com@dns1.name-services.com.:

mycustomdomain.com. 1800 IN A 216.239.36.21
mycustomdomain.com. 1800 IN A 216.239.34.21
mycustomdomain.com. 1800 IN A 216.239.38.21
mycustomdomain.com. 1800 IN A 216.239.32.21

mycustomdomain.com@dns2.name-services.com.:

mycustomdomain.com. 1800 IN A 216.239.36.21
mycustomdomain.com. 1800 IN A 216.239.34.21
mycustomdomain.com. 1800 IN A 216.239.32.21
mycustomdomain.com. 1800 IN A 216.239.38.21

mycustomdomain.com@dns3.name-services.com.:

mycustomdomain.com. 1800 IN A 216.239.36.21
mycustomdomain.com. 1800 IN A 216.239.32.21
mycustomdomain.com. 1800 IN A 216.239.34.21
mycustomdomain.com. 1800 IN A 216.239.38.21

mycustomdomain.com@dns4.name-services.com.:

mycustomdomain.com. 1800 IN A 216.239.36.21
mycustomdomain.com. 1800 IN A 216.239.34.21
mycustomdomain.com. 1800 IN A 216.239.32.21
mycustomdomain.com. 1800 IN A 216.239.38.21

mycustomdomain.com@dns5.name-services.com.:

org. 3601 IN
SOA dns1.name-services.com. info.name-services.com. 2010 10800 3600 604800 3600


www.mycustomdomain.com@dns1.name-services.com.:

www.mycustomdomain.com. 1800 IN CNAME ghs.google.com.

www.mycustomdomain.com@dns2.name-services.com.:

www.mycustomdomain.com. 1800 IN CNAME ghs.google.com.

www.mycustomdomain.com@dns3.name-services.com.:

www.mycustomdomain.com. 1800 IN CNAME ghs.google.com.

www.mycustomdomain.com@dns4.name-services.com.:

www.mycustomdomain.com. 1800 IN CNAME ghs.google.com.

www.mycustomdomain.com@dns5.name-services.com.:

org. 3601 IN
SOA dns1.name-services.com. info.name-services.com. 2010 10800 3600 604800 3600
Right now, it appears that server "dns5" is consistently broken.

It's possible that this problem will affect more eNom customers, as the day progresses, cached DNS addresses expire, and readers of various eNom hosted domains request DNS addresses. I hope that eNom Customer Service can react to this problem more promptly than they have reacted to the immediately previous problem.

>> Top

Thursday, 12 July 2012

Custom Domain Publishing, And "403 Forbidden"

Next to its immediate cousin error
Another blog is already hosted at this address
I don't know of too many more frustrating Blogger error states than seeing
403 Forbidden
Most cases of "403 Forbidden", seen and discussed recently in Blogger Help Forum: Something Is Broken, have geographical affinity - and are typically transient - and apply to blogs published to "blogspot.com".

Some cases of "403 Forbidden" however, will involve custom domain publishing, where the blog owner should - but most likely will not - see
Another blog is already hosted at this address
When publishing the blog to the domain.

In some cases, when publishing a blog to an incorrectly setup custom domain, the custom domain publishing wizard will fail to detect the incorrect DNS addresses. Instead of the blog owner, seeing immediately
Another blog is already hosted at this address.
The owner will see
Your blog has been published.
Later, the blog owner - and all potential blog readers - see the secondary symptom
403 Forbidden
.




Here, we have an excellent example of the problem - diagnosis, and treatment.

Let's first look at a Dig log extract.
jubileeventure.org.uk.    86400    IN    A    94.136.40.75
www.jubileeventure.org.uk. 86400 IN A 94.136.40.75

Now, an HTTP trace extract, showing unsuccessful access to the domain.
Sending request:

GET / HTTP/1.1
Host: www.jubileeventure.org.uk
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
Referer: http://www.rexswain.com/httpview.html
Connection: close

• Finding host IP address...
• Host IP address = 94.136.40.75
• Finding TCP protocol...
• Binding to local socket...
• Connecting to host...
• Sending request...
• Waiting for response...
Receiving Header:
HTTP/1.1·403·Forbidden(CR)(LF)
The solution to this problem involves a standard misconfigured domain diagnosis (excerpted here), and requires DNS address correction.
Here's what you have:

jubileeventure.org.uk. 86400 IN A 94.136.40.75
www.jubileeventure.org.uk. 86400 IN A 94.136.40.75

Google custom domain publishing requires properly setup referrals to Google servers. "94.136.40.75" is not a Google server.

Here's what you need:

jubileeventure.org.uk. 86400 IN A 216.239.32.21
jubileeventure.org.uk. 86400 IN A 216.239.34.21
jubileeventure.org.uk. 86400 IN A 216.239.36.21
jubileeventure.org.uk. 86400 IN A 216.239.38.21
www.jubileeventure.org.uk. 86400 IN CNAME ghs.google.com.

>> Top

Monday, 2 July 2012

eNom: Fix Your DNS Servers!

For over 2 months, we've been seeing reports from blog owners who published their blogs to custom domains, with domain DNS hosted by eNom, in Blogger Help Forum: Something Is Broken.
I bought my domain name through Blogger,last week. It is being hosted by eNom. Ever since I bought it some of my followers, and sometimes myself, can't access my site. There is either a DNS search or a "Ooops, Google Chrome can't find..."

I tried contacting eNom, and they said they can see my site and that all of my settings are correct. They say it must be Google's problem.
The keyword here is "sometimes".
Ever since I bought it some of my followers, and sometimes myself, can't access my site.

A simple Dig, for the domain in question, will frequently show normal results. The usual DNS configuration, for a domain purchased using "Buy a domain", will be asymmetrical aka "Google Apps".
enomhosteddomain.com. 1800 IN A 216.239.32.21
enomhosteddomain.com. 1800 IN A 216.239.34.21
enomhosteddomain.com. 1800 IN A 216.239.36.21
enomhosteddomain.com. 1800 IN A 216.239.38.21
www.enomhosteddomain.com. 1800 IN CNAME ghs.google.com.
The problem, which not so many people appreciate, is that eNom uses multiple DNS servers, possibly geographically separated. This is normal DNS hosting technique, and guarantees redundancy if one data center goes offline.

However, for redundancy to work, all DNS servers have to be kept consistently synchronised. If we examine the 5 eNom DNS servers individually, we will frequently see discrepancies.
enomhosteddomain.com @ dns1.name-services.com.:

enomhosteddomain.com. 1800 IN A 216.239.32.21
enomhosteddomain.com. 1800 IN A 216.239.34.21
enomhosteddomain.com. 1800 IN A 216.239.36.21
enomhosteddomain.com. 1800 IN A 216.239.38.21
enomhosteddomain.com. 3600 IN NS dns1.name-services.com.
enomhosteddomain.com. 3600 IN NS dns2.name-services.com.
enomhosteddomain.com. 3600 IN NS dns3.name-services.com.
enomhosteddomain.com. 3600 IN NS dns4.name-services.com.
enomhosteddomain.com. 3600 IN NS dns5.name-services.com.

enomhosteddomain.com @ dns2.name-services.com.:

enomhosteddomain.com. 1800 IN A 216.239.34.21
enomhosteddomain.com. 1800 IN A 216.239.38.21
enomhosteddomain.com. 1800 IN A 216.239.32.21
enomhosteddomain.com. 1800 IN A 216.239.36.21

enomhosteddomain.com @ dns3.name-services.com.:

com. 3601 IN SOA dns1.name-services.com. info.name-services.com. 2010 10001 1801 604801 181

enomhosteddomain.com @ dns4.name-services.com.:

enomhosteddomain.com. 1800 IN A 216.239.32.21
enomhosteddomain.com. 1800 IN A 216.239.36.21
enomhosteddomain.com. 1800 IN A 216.239.34.21
enomhosteddomain.com. 1800 IN A 216.239.38.21

enomhosteddomain.com @ dns5.name-services.com.:

enomhosteddomain.com. 1800 IN A 216.239.32.21
enomhosteddomain.com. 1800 IN A 216.239.34.21
enomhosteddomain.com. 1800 IN A 216.239.36.21
enomhosteddomain.com. 1800 IN A 216.239.38.21
enomhosteddomain.com. 3600 IN NS dns1.name-services.com.
enomhosteddomain.com. 3600 IN NS dns2.name-services.com.
enomhosteddomain.com. 3600 IN NS dns3.name-services.com.
enomhosteddomain.com. 3600 IN NS dns4.name-services.com.
enomhosteddomain.com. 3600 IN NS dns5.name-services.com.


www.enomhosteddomain.com @ dns1.name-services.com.:

www.enomhosteddomain.com. 1800 IN CNAME ghs.google.com.

www.enomhosteddomain.com @ dns2.name-services.com.:

www.enomhosteddomain.com. 1800 IN CNAME ghs.google.com.

www.enomhosteddomain.com @ dns3.name-services.com.:

com. 3601 IN SOA dns1.name-services.com. info.name-services.com. 2010 10001 1801 604801 181

www.enomhosteddomain.com @ dns4.name-services.com.:

www.enomhosteddomain.com. 1800 IN CNAME ghs.google.com.

www.enomhosteddomain.com @ dns5.name-services.com.:

www.enomhosteddomain.com. 1800 IN CNAME ghs.google.com.

This is one of the more subtle discrepancies, which I have observed, in the past couple months - only DNS Server #3 is out of synch, in this case. But that's enough, to make the domain unreliable.
The problem is intermittent. All of a sudden my site loads, but 10 minutes ago it didn't.
That's one eNom customer, out of over a dozen, which I have documented. And that's one eNom customer, who should be complaining, to someone above eNom Customer Service.

eNom: fix your servers!


(Update 2012/07/03): Suspicion that the problem is related to Anycast DNS led me to a bud, who is a fellow TC, and a network expert in India, and who provided an intriguing blog post, neatly diagnosing the underlying problem. It appears that eNom server monitoring policies may be a bit superficial.


Use these links, for convenient reference:

>> Top

Tuesday, 19 June 2012

Custom Domain Diagnoses - Identify DNS Address Inconsistencies

One of the more intriguing causes of intermittent custom domain problems starts with inconsistent DNS server configuration. Recently, eNom, one of the "partners" in "Buy a domain", has been serving inconsistent DNS configurations, from time to time - including one very blatant episode the afternoon of 6/18/2012, which was reported by several dozen angry blog owners.

Detecting, and diagnosing, the inconsistencies is typically a complicated process.
  1. Identify the domain authority servers, typically using a Who Is lookup.
  2. Dig each domain address (typically "naked domain" and "www" aliases), from each of the identified domain authority servers.
  3. Extract and aggregate each Dig log.
  4. Compare aggregated Dig snippets.
This was not a task for the faint of heart, or tech challenged, blog owner.

Recently, I was given a handy tool which does all of this, in one quick GUI transaction.

The Dig Web Interface, yet another free online tool, provides us the ability to diagnose inconsistent DNS servers - such as the problem eNom seems to have, in a 30 second transaction.
  1. Provide the "naked domain" and "www" aliases.
  2. Select "A" for "Type" ("A" / "CNAME" / "NS" lookups).
  3. Select "Authoritative" for "Nameservers".
  4. Hit "Dig".
Finally, just copy the log produced, for examination.

It's not a fancy tool, but it does the job - very well. Here, we see the log for this domain, "nitecruzr.net".
nitecruzr.net@ns11.domaincontrol.com.:
nitecruzr.net. 3600 IN A 216.239.36.21
nitecruzr.net. 3600 IN A 216.239.32.21
nitecruzr.net. 3600 IN A 216.239.34.21
nitecruzr.net. 3600 IN A 216.239.38.21
nitecruzr.net. 3600 IN NS ns54.domaincontrol.com.
nitecruzr.net. 3600 IN NS ns53.domaincontrol.com.
nitecruzr.net. 3600 IN NS ns12.domaincontrol.com.
nitecruzr.net. 3600 IN NS ns11.domaincontrol.com.


nitecruzr.net@ns12.domaincontrol.com.:
nitecruzr.net. 3600 IN A 216.239.36.21
nitecruzr.net. 3600 IN A 216.239.32.21
nitecruzr.net. 3600 IN A 216.239.34.21
nitecruzr.net. 3600 IN A 216.239.38.21
nitecruzr.net. 3600 IN NS ns54.domaincontrol.com.
nitecruzr.net. 3600 IN NS ns53.domaincontrol.com.
nitecruzr.net. 3600 IN NS ns12.domaincontrol.com.
nitecruzr.net. 3600 IN NS ns11.domaincontrol.com.


nitecruzr.net@ns53.domaincontrol.com.:
nitecruzr.net. 3600 IN A 216.239.36.21
nitecruzr.net. 3600 IN A 216.239.34.21
nitecruzr.net. 3600 IN A 216.239.38.21
nitecruzr.net. 3600 IN A 216.239.32.21
nitecruzr.net. 3600 IN NS ns54.domaincontrol.com.
nitecruzr.net. 3600 IN NS ns53.domaincontrol.com.
nitecruzr.net. 3600 IN NS ns12.domaincontrol.com.
nitecruzr.net. 3600 IN NS ns11.domaincontrol.com.


nitecruzr.net@ns54.domaincontrol.com.:
nitecruzr.net. 3600 IN A 216.239.36.21
nitecruzr.net. 3600 IN A 216.239.34.21
nitecruzr.net. 3600 IN A 216.239.38.21
nitecruzr.net. 3600 IN A 216.239.32.21
nitecruzr.net. 3600 IN NS ns54.domaincontrol.com.
nitecruzr.net. 3600 IN NS ns53.domaincontrol.com.
nitecruzr.net. 3600 IN NS ns12.domaincontrol.com.
nitecruzr.net. 3600 IN NS ns11.domaincontrol.com.


www.nitecruzr.net@ns11.domaincontrol.com.:
www.nitecruzr.net. 3600 IN CNAME ghs.google.com.


www.nitecruzr.net@ns12.domaincontrol.com.:
www.nitecruzr.net. 3600 IN CNAME ghs.google.com.


www.nitecruzr.net@ns53.domaincontrol.com.:
www.nitecruzr.net. 3600 IN CNAME ghs.google.com.


www.nitecruzr.net@ns54.domaincontrol.com.:
www.nitecruzr.net. 3600 IN CNAME ghs.google.com.
The log is not complicated, to parse. For each URL, each authority server is identified, and Dug. In the case of this domain, hosted on GoDaddy, we see each URL, Dug from each of 4 authority servers, one by one.

If a DNS inconsistency existed, the above log would show the differing DNS addresses - such as eNom hosted domains show, from time to time. Given this tool, it may be easier to look for DNS inconsistencies, when problems with custom domains are reported, in Blogger Help Forum: Something Is Broken.

>> Top