DNS Error
DNS Error: SERVFAIL
The DNS server encountered an internal error and could not process the query — distinct from NXDOMAIN, which is a definitive "doesn't exist" answer.
What This Error Means
SERVFAIL means the DNS server itself hit a problem while trying to resolve the query — this could be at the resolver level (your configured DNS server is misconfigured or overloaded) or at the authoritative nameserver level (the domain's own DNS servers are broken or misconfigured, e.g. a broken DNSSEC signature).
Why It Occurs
Common causes include the domain's authoritative nameservers being misconfigured or unreachable, a broken DNSSEC configuration causing validation failures, or the resolver you're querying being overloaded or having its own internal issue.
Symptoms
- ⚠ `dig`/`nslookup` explicitly show "SERVFAIL" in the status line
- ⚠ Intermittent — may work against one resolver but fail against another
Common Causes
- • The domain's authoritative nameservers are misconfigured, unreachable, or returning malformed responses
- • Broken DNSSEC signatures causing validating resolvers to reject the response
- • The specific DNS resolver being queried is overloaded or has an internal fault
How to Fix It
- Test against a different public resolver to isolate whether it's resolver-specific: `dig example.com @1.1.1.1` vs `dig example.com @8.8.8.8`
- If it fails against multiple independent resolvers, the problem is with the domain's own authoritative nameservers — check them directly: `dig example.com @ns1.the-domains-nameserver.com`
- If DNSSEC is enabled, check DNSSEC validation status: `dig +dnssec example.com` and check for signature/validation errors
- If you control the domain's DNS, verify the nameserver records at your registrar match the ones actually hosting the zone, and that the authoritative servers are actually reachable and serving the zone correctly
| Command | Purpose |
|---|---|
| dig example.com @1.1.1.1 | Test against a specific resolver to isolate resolver-side vs. authoritative-side issues |
| dig +dnssec example.com | Check for DNSSEC validation failures |
Verification
- ✓ Queries against multiple resolvers all return a valid answer instead of SERVFAIL
Prevention
- → Monitor authoritative nameserver health independently of the main website/service monitoring
- → Test DNSSEC changes carefully in a non-production zone before applying to a live domain, since misconfigured DNSSEC is a common self-inflicted SERVFAIL cause