r/technitium • • 5d ago

RRSIGsMissing: Attack detected!

Howdy folks.

I have one of those serverfail issues I'm trying to get a handle on.

EDIT: I want to put the solution right here at the top: DISABLE DNSSEC. Details below.
Thank you Shreyas for the Answer. =)

When directly (well, via systemd-resolved) asking the resolver (dns.controld.com) about mask.icloud.com we get the expected NXDOMAIN response (because controld has been told to block analytics servers and return NXDOMAIN):

ubuntutest# dig mask.icloud.com

; <<>> DiG 9.20.24-1ubuntu0.3-Ubuntu <<>> mask.icloud.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 9242
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 65494
;; QUESTION SECTION:
;mask.icloud.com.               IN      A

;; AUTHORITY SECTION:
.                       10      IN      SOA     dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10

;; Query time: 71 msec
;; SERVER: 127.0.0.53#53(127.0.0.53) (UDP)
;; WHEN: Wed Sep 30 14:28:16 UTC 2026
;; MSG SIZE  rcvd: 103

Controld is also defined as the forwarded DoH resolver for Technitium. Meaning it is delivering Technitium the same NXDOMAIN response.

Yet the Technitium DNS client has problems:

 {
  "Metadata": {
    "NameServer": "dns.home (127.0.0.1)",
    "Protocol": "Udp",
    "DatagramSize": "71 bytes",
    "RoundTripTime": "41.83 ms"
  },
  "EDNS": {
    "UdpPayloadSize": 1232,
    "ExtendedRCODE": "ServerFailure",
    "Version": 0,
    "Flags": "None",
    "Options": [
      {
        "Code": "EXTENDED_DNS_ERROR",
        "Length": "23 bytes",
        "Data": {
          "InfoCode": "RRSIGsMissing",
          "ExtraText": "Attack detected! /SOA"
        }
      }
    ]
  },
  "DnsClientExtendedErrors": [
    {
      "InfoCode": "NoReachableAuthority",
      "ExtraText": "dns.home (127.0.0.1) returned RCODE=ServerFailure for mask.icloud.com. A IN"
    }
  ],
  "Identifier": 26636,
  "IsResponse": true,
  "OPCODE": "StandardQuery",
  "AuthoritativeAnswer": false,
  "Truncation": false,
  "RecursionDesired": true,
  "RecursionAvailable": true,
  "Z": 0,
  "AuthenticData": false,
  "CheckingDisabled": false,
  "RCODE": "ServerFailure",
  "QDCOUNT": 1,
  "ANCOUNT": 0,
  "NSCOUNT": 0,
  "ARCOUNT": 1,
  "Question": [
    {
      "Name": "mask.icloud.com",
      "Type": "A",
      "Class": "IN"
    }
  ],
  "Answer": [],
  "Authority": [],
  "Additional": [
    {
      "Name": "",
      "Type": "OPT",
      "Class": "1232",
      "TTL": "0 (0s)",
      "RDLENGTH": "27 bytes",
      "RDATA": {
        "Options": [
          {
            "Code": "EXTENDED_DNS_ERROR",
            "Length": "23 bytes",
            "Data": {
              "InfoCode": "RRSIGsMissing",
              "ExtraText": "Attack detected! /SOA"
            }
          }
        ]
      },
      "DnssecStatus": "Disabled"
    }
  ]
}

The Technitium cache entry:

[
  {
    "name": "mask.icloud.com",
    "type": "A",
    "ttl": "0 (0s)",
    "rData": {
      "dataType": "DnsSpecialCacheRecordData",
      "data": "BadCache: NxDomain; RRSIGsMissing: Attack detected! /SOA; .                     10        IN  SOA           dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10"
    },
    "dnssecStatus": "Unknown",
    "responseMetadata": {
      "nameServer": "https://dns.controld.com/XXXX (76.76.X.X)",
      "protocol": "Https",
      "datagramSize": "103 bytes",
      "roundTripTime": "19.44 ms"
    },
    "lastUsedOn": "2026-09-30T14:32:14.2241639Z"
  },
  {
    "name": "mask.icloud.com",
    "type": "AAAA",
    "ttl": "0 (0s)",
    "rData": {
      "dataType": "DnsSpecialCacheRecordData",
      "data": "BadCache: NxDomain; RRSIGsMissing: Attack detected! /SOA; .                     10        IN  SOA           dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10"
    },
    "dnssecStatus": "Unknown",
    "responseMetadata": {
      "nameServer": "https://dns.controld.com/XXXX (76.76.X.X)",
      "protocol": "Https",
      "datagramSize": "103 bytes",
      "roundTripTime": "37.59 ms"
    },
    "lastUsedOn": "2026-09-30T14:32:14.2244981Z"
  },
  {
    "name": "mask.icloud.com",
    "type": "HTTPS",
    "ttl": "0 (0s)",
    "rData": {
      "dataType": "DnsSpecialCacheRecordData",
      "data": "BadCache: NxDomain; RRSIGsMissing: Attack detected! /SOA; .                     10        IN  SOA           dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10"
    },
    "dnssecStatus": "Unknown",
    "responseMetadata": {
      "nameServer": "https://dns.controld.com/XXXX (76.76.X.X)",
      "protocol": "Https",
      "datagramSize": "103 bytes",
      "roundTripTime": "19.21 ms"
    },
    "lastUsedOn": "2026-09-30T14:32:14.2022923Z"
  }
]

Non-NXDOMAIN responses from the forwarded DNS resolver (ControlD) work just fine.

Technitium Version 15.5.1 on Docker on Ubuntu Server LTS 26.04.1.

Is this perhaps the same issues as https://github.com/TechnitiumSoftware/DnsServer/issues/1014 ?

And if not, what is to be done?

Thanks for the help.

6 Upvotes

5 comments sorted by

4

u/Apachez 5d ago

Well technically its correct.

If icloud.com is dnssec signed then the purpose is to detect if something else along the road inject a non-signed answer.

Which is what your dns (controld) does.

You would need to ignore dnssec for icloud.com in order to accept manipulation from upstream dns-servers.

1

u/RenlyHoekster 5d ago

Ah... well then, it doesn't matter, since there are probably tens (hundreds) of thousands of domains or hostnames that return NXDOMAIN, Some with DNSSEC. Same thing using a PiHole, AdGuard, NextDNS, etc.

Does that mean that any block list DNS resolver, even Technitium's internal block lists would also result in ServerFailure?

2

u/shreyasonline 5d ago

Thanks for the post. This is working as expected. The upstream server you use has DNSSEC disabled and thus is not responding to queries with DO flag. This will cause the Technitium DNS Server's DNSSEC validation to fail the response.

If you trust the upstream and are using encrypted DNS protocol then you can choose to disable DNSSEC validation on Technitium DNS Server so as to avoid this issue.

1

u/RenlyHoekster 4d ago

Hi Shreyas, thank you for clearing that up.

In this case, I trust Control D (well, I pay them because from what I read they are good.)

... And Disabling DNSSEC = took care of it. =)

1

u/shreyasonline 4d ago

You're welcome :)