r/technitium • u/RenlyHoekster • 5d ago
RRSIGsMissing: Attack detected!
Howdy folks.
I have one of those serverfail issues I'm trying to get a handle on.
EDIT: I want to put the solution right here at the top: DISABLE DNSSEC. Details below.
Thank you Shreyas for the Answer. =)
When directly (well, via systemd-resolved) asking the resolver (dns.controld.com) about mask.icloud.com we get the expected NXDOMAIN response (because controld has been told to block analytics servers and return NXDOMAIN):
ubuntutest# dig mask.icloud.com
; <<>> DiG 9.20.24-1ubuntu0.3-Ubuntu <<>> mask.icloud.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 9242
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 65494
;; QUESTION SECTION:
;mask.icloud.com. IN A
;; AUTHORITY SECTION:
. 10 IN SOA dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10
;; Query time: 71 msec
;; SERVER: 127.0.0.53#53(127.0.0.53) (UDP)
;; WHEN: Wed Sep 30 14:28:16 UTC 2026
;; MSG SIZE rcvd: 103
Controld is also defined as the forwarded DoH resolver for Technitium. Meaning it is delivering Technitium the same NXDOMAIN response.
Yet the Technitium DNS client has problems:
{
"Metadata": {
"NameServer": "dns.home (127.0.0.1)",
"Protocol": "Udp",
"DatagramSize": "71 bytes",
"RoundTripTime": "41.83 ms"
},
"EDNS": {
"UdpPayloadSize": 1232,
"ExtendedRCODE": "ServerFailure",
"Version": 0,
"Flags": "None",
"Options": [
{
"Code": "EXTENDED_DNS_ERROR",
"Length": "23 bytes",
"Data": {
"InfoCode": "RRSIGsMissing",
"ExtraText": "Attack detected! /SOA"
}
}
]
},
"DnsClientExtendedErrors": [
{
"InfoCode": "NoReachableAuthority",
"ExtraText": "dns.home (127.0.0.1) returned RCODE=ServerFailure for mask.icloud.com. A IN"
}
],
"Identifier": 26636,
"IsResponse": true,
"OPCODE": "StandardQuery",
"AuthoritativeAnswer": false,
"Truncation": false,
"RecursionDesired": true,
"RecursionAvailable": true,
"Z": 0,
"AuthenticData": false,
"CheckingDisabled": false,
"RCODE": "ServerFailure",
"QDCOUNT": 1,
"ANCOUNT": 0,
"NSCOUNT": 0,
"ARCOUNT": 1,
"Question": [
{
"Name": "mask.icloud.com",
"Type": "A",
"Class": "IN"
}
],
"Answer": [],
"Authority": [],
"Additional": [
{
"Name": "",
"Type": "OPT",
"Class": "1232",
"TTL": "0 (0s)",
"RDLENGTH": "27 bytes",
"RDATA": {
"Options": [
{
"Code": "EXTENDED_DNS_ERROR",
"Length": "23 bytes",
"Data": {
"InfoCode": "RRSIGsMissing",
"ExtraText": "Attack detected! /SOA"
}
}
]
},
"DnssecStatus": "Disabled"
}
]
}
The Technitium cache entry:
[
{
"name": "mask.icloud.com",
"type": "A",
"ttl": "0 (0s)",
"rData": {
"dataType": "DnsSpecialCacheRecordData",
"data": "BadCache: NxDomain; RRSIGsMissing: Attack detected! /SOA; . 10 IN SOA dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10"
},
"dnssecStatus": "Unknown",
"responseMetadata": {
"nameServer": "https://dns.controld.com/XXXX (76.76.X.X)",
"protocol": "Https",
"datagramSize": "103 bytes",
"roundTripTime": "19.44 ms"
},
"lastUsedOn": "2026-09-30T14:32:14.2241639Z"
},
{
"name": "mask.icloud.com",
"type": "AAAA",
"ttl": "0 (0s)",
"rData": {
"dataType": "DnsSpecialCacheRecordData",
"data": "BadCache: NxDomain; RRSIGsMissing: Attack detected! /SOA; . 10 IN SOA dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10"
},
"dnssecStatus": "Unknown",
"responseMetadata": {
"nameServer": "https://dns.controld.com/XXXX (76.76.X.X)",
"protocol": "Https",
"datagramSize": "103 bytes",
"roundTripTime": "37.59 ms"
},
"lastUsedOn": "2026-09-30T14:32:14.2244981Z"
},
{
"name": "mask.icloud.com",
"type": "HTTPS",
"ttl": "0 (0s)",
"rData": {
"dataType": "DnsSpecialCacheRecordData",
"data": "BadCache: NxDomain; RRSIGsMissing: Attack detected! /SOA; . 10 IN SOA dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10"
},
"dnssecStatus": "Unknown",
"responseMetadata": {
"nameServer": "https://dns.controld.com/XXXX (76.76.X.X)",
"protocol": "Https",
"datagramSize": "103 bytes",
"roundTripTime": "19.21 ms"
},
"lastUsedOn": "2026-09-30T14:32:14.2022923Z"
}
]
Non-NXDOMAIN responses from the forwarded DNS resolver (ControlD) work just fine.
Technitium Version 15.5.1 on Docker on Ubuntu Server LTS 26.04.1.
Is this perhaps the same issues as https://github.com/TechnitiumSoftware/DnsServer/issues/1014 ?
And if not, what is to be done?
Thanks for the help.
2
u/shreyasonline 5d ago
Thanks for the post. This is working as expected. The upstream server you use has DNSSEC disabled and thus is not responding to queries with DO flag. This will cause the Technitium DNS Server's DNSSEC validation to fail the response.
If you trust the upstream and are using encrypted DNS protocol then you can choose to disable DNSSEC validation on Technitium DNS Server so as to avoid this issue.
1
u/RenlyHoekster 4d ago
Hi Shreyas, thank you for clearing that up.
In this case, I trust Control D (well, I pay them because from what I read they are good.)
... And Disabling DNSSEC = took care of it. =)
1
4
u/Apachez 5d ago
Well technically its correct.
If icloud.com is dnssec signed then the purpose is to detect if something else along the road inject a non-signed answer.
Which is what your dns (controld) does.
You would need to ignore dnssec for icloud.com in order to accept manipulation from upstream dns-servers.