Skip to content

TroubleshootingDNS problems

Domain not resolving? Diagnose DNS step by step

Fix a domain that does not resolve or points to the wrong server: read NXDOMAIN and SERVFAIL, check delegation, registry status, DNSSEC and local DNS caches.

  • Intermediate
  • 12 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Debian 13, Windows 11, macOS Tahoe 26

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Before you start
  2. Step 1: Ask a public resolver
  3. Step 2: Check the delegation and the registry status
  4. Step 3: Ask the authoritative nameserver
  5. Step 4: Check DNSSEC
  6. Step 5: Clear your own caches
  7. Troubleshooting
  8. When to open a ticket
  9. Next steps

When a domain does not resolve, or resolves to the wrong address, the fault sits somewhere in a chain: the registry delegates the domain to nameservers, the nameservers hold the records, resolvers cache the answers, and your computer caches them again. This guide checks each link. Replace example.com and 203.0.113.10 with your own values.

Before you start

You need dig (in the bind9-dnsutils package on Ubuntu and Debian, built into macOS) or, on Windows, PowerShell's Resolve-DnsName. Note what you see: an error page, a different site, or nothing at all.

Step 1: Ask a public resolver

Linux and macOS

Bash
dig example.com A @1.1.1.1
dig example.com A @8.8.8.8

Windows

PowerShell
Resolve-DnsName example.com -Type A -Server 1.1.1.1
Resolve-DnsName example.com -Type A -Server 8.8.8.8

Read the status: in the header of the dig answer:

  • NOERROR with the right address: DNS works; the problem is on your computer (Step 5) or not DNS at all.
  • NOERROR with a wrong address: an old or wrong record (Step 3).
  • NXDOMAIN: the name does not exist: a typo, a missing record or a broken delegation (Steps 2 and 3).
  • SERVFAIL: resolvers cannot get a valid answer: often DNSSEC (Step 4) or unreachable nameservers.

Step 2: Check the delegation and the registry status

Follow the chain from the root down:

Bash
dig +trace example.com

The last section shows which nameservers the registry delegates to and what they answered. Compare them with the nameservers you set in Domains › My Domains › Manage Domain › Nameservers.

Then look up the registration data at lookup.icann.org. Check:

  • Expiry date: an expired domain is removed from DNS until it is renewed.
  • Status: clientHold or serverHold means the registry does not publish the domain, for example because the registrant email was not verified or the domain expired. Confirm the verification email or renew the domain.
  • Nameservers: the ones listed must be the ones you intended.

Step 3: Ask the authoritative nameserver

Query your DNS host directly, which bypasses every cache:

Bash
dig NS example.com +short
dig example.com A @ns1.example-dns.net
dig www.example.com A @ns1.example-dns.net

Replace ns1.example-dns.net with one of the nameservers from the first command.

  • The answer is right: the record is fine; resolvers still cache the old one. Wait for the TTL shown in the answer.
  • The answer is wrong or missing: fix the record at your DNS host. Remember that changes made at a provider you no longer delegate to have no effect.
  • No answer (timeout): the nameserver does not serve your zone. Add the zone at the DNS host or switch the nameservers.

Also check the AAAA record: a stale IPv6 address sends some visitors to the wrong server even when the A record is correct.

Bash
dig example.com AAAA @ns1.example-dns.net

Step 4: Check DNSSEC

If public resolvers return SERVFAIL but a query with checking disabled works, DNSSEC validation fails:

Bash
dig example.com A @1.1.1.1 +cd
dig DS example.com +short
delv example.com A

The most common cause is a DS record left at the registry after you moved DNS to another host. Remove the old DS record at the registrar, or publish the new one from your DNS host if it signs the zone. Tools such as DNSViz show the chain of trust graphically.

Step 5: Clear your own caches

When public resolvers give the right answer but your computer does not, flush the local cache and check the hosts file for leftovers from testing:

Windows

PowerShell
ipconfig /flushdns
Get-Content C:\Windows\System32\drivers\etc\hosts

macOS

Bash
sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder
cat /etc/hosts

Linux

Bash
sudo resolvectl flush-caches
cat /etc/hosts

Browsers keep their own DNS cache too; restart the browser or try a private window.

Troubleshooting

Only www fails. The www record is missing or points to a name that does not resolve. Add an A record or a CNAME to the root domain.

Email works, the website does not (or the other way round). Website and email use different records: A/AAAA for the site, MX for mail. Check each one at the authoritative nameserver.

It works with one nameserver and not the other. Your DNS host's servers are out of sync. Query each NS directly and contact the DNS host.

When to open a ticket

If the domain is registered with HyperDC and the registry status, the nameservers or the DS record look wrong and you cannot change them in the client area, open a ticket with the domain selected. Include the output of dig +trace example.com and what you expected to see.

Next steps

Frequently asked questions

What do NXDOMAIN and SERVFAIL mean?

NXDOMAIN means the name does not exist in DNS: a typo, a missing record or a domain that is not delegated. SERVFAIL means the resolver could not get a valid answer, often because of a DNSSEC mismatch or nameservers that do not respond.

I changed a record an hour ago and still see the old IP. Why?

Resolvers keep the old answer until its TTL expires, and your computer and browser may cache it as well. Query your authoritative nameserver directly to confirm the change, then wait out the old TTL or flush local caches.

Why does the domain work for me but not for others?

You may have an entry in your hosts file, or your resolver already has the new answer while others still have the old one. Test with public resolvers and from another network.

My domain stopped resolving after it expired. What now?

An expired domain is taken out of DNS. Renew it in the client area; resolution returns once the registry has processed the renewal, which can take some hours.

What is a DS record and why does it matter?

A DS record at the registry links your domain to DNSSEC keys at your DNS host. If you move DNS to a new host and leave an old DS record, validating resolvers return SERVFAIL. Remove or update it at the registrar.

Sources

Generar contraseña

Please confirm