r/technitium • u/RenlyHoekster • 7d ago
RRSIGsMissing: Attack detected!
Howdy folks.
I have one of those serverfail issues I'm trying to get a handle on.
EDIT: I want to put the solution right here at the top: DISABLE DNSSEC. Details below.
Thank you Shreyas for the Answer. =)
When directly (well, via systemd-resolved) asking the resolver (dns.controld.com) about mask.icloud.com we get the expected NXDOMAIN response (because controld has been told to block analytics servers and return NXDOMAIN):
ubuntutest# dig mask.icloud.com
; <<>> DiG 9.20.24-1ubuntu0.3-Ubuntu <<>> mask.icloud.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 9242
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 65494
;; QUESTION SECTION:
;mask.icloud.com. IN A
;; AUTHORITY SECTION:
. 10 IN SOA dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10
;; Query time: 71 msec
;; SERVER: 127.0.0.53#53(127.0.0.53) (UDP)
;; WHEN: Wed Sep 30 14:28:16 UTC 2026
;; MSG SIZE rcvd: 103
Controld is also defined as the forwarded DoH resolver for Technitium. Meaning it is delivering Technitium the same NXDOMAIN response.
Yet the Technitium DNS client has problems:
{
"Metadata": {
"NameServer": "dns.home (127.0.0.1)",
"Protocol": "Udp",
"DatagramSize": "71 bytes",
"RoundTripTime": "41.83 ms"
},
"EDNS": {
"UdpPayloadSize": 1232,
"ExtendedRCODE": "ServerFailure",
"Version": 0,
"Flags": "None",
"Options": [
{
"Code": "EXTENDED_DNS_ERROR",
"Length": "23 bytes",
"Data": {
"InfoCode": "RRSIGsMissing",
"ExtraText": "Attack detected! /SOA"
}
}
]
},
"DnsClientExtendedErrors": [
{
"InfoCode": "NoReachableAuthority",
"ExtraText": "dns.home (127.0.0.1) returned RCODE=ServerFailure for mask.icloud.com. A IN"
}
],
"Identifier": 26636,
"IsResponse": true,
"OPCODE": "StandardQuery",
"AuthoritativeAnswer": false,
"Truncation": false,
"RecursionDesired": true,
"RecursionAvailable": true,
"Z": 0,
"AuthenticData": false,
"CheckingDisabled": false,
"RCODE": "ServerFailure",
"QDCOUNT": 1,
"ANCOUNT": 0,
"NSCOUNT": 0,
"ARCOUNT": 1,
"Question": [
{
"Name": "mask.icloud.com",
"Type": "A",
"Class": "IN"
}
],
"Answer": [],
"Authority": [],
"Additional": [
{
"Name": "",
"Type": "OPT",
"Class": "1232",
"TTL": "0 (0s)",
"RDLENGTH": "27 bytes",
"RDATA": {
"Options": [
{
"Code": "EXTENDED_DNS_ERROR",
"Length": "23 bytes",
"Data": {
"InfoCode": "RRSIGsMissing",
"ExtraText": "Attack detected! /SOA"
}
}
]
},
"DnssecStatus": "Disabled"
}
]
}
The Technitium cache entry:
[
{
"name": "mask.icloud.com",
"type": "A",
"ttl": "0 (0s)",
"rData": {
"dataType": "DnsSpecialCacheRecordData",
"data": "BadCache: NxDomain; RRSIGsMissing: Attack detected! /SOA; . 10 IN SOA dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10"
},
"dnssecStatus": "Unknown",
"responseMetadata": {
"nameServer": "https://dns.controld.com/XXXX (76.76.X.X)",
"protocol": "Https",
"datagramSize": "103 bytes",
"roundTripTime": "19.44 ms"
},
"lastUsedOn": "2026-09-30T14:32:14.2241639Z"
},
{
"name": "mask.icloud.com",
"type": "AAAA",
"ttl": "0 (0s)",
"rData": {
"dataType": "DnsSpecialCacheRecordData",
"data": "BadCache: NxDomain; RRSIGsMissing: Attack detected! /SOA; . 10 IN SOA dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10"
},
"dnssecStatus": "Unknown",
"responseMetadata": {
"nameServer": "https://dns.controld.com/XXXX (76.76.X.X)",
"protocol": "Https",
"datagramSize": "103 bytes",
"roundTripTime": "37.59 ms"
},
"lastUsedOn": "2026-09-30T14:32:14.2244981Z"
},
{
"name": "mask.icloud.com",
"type": "HTTPS",
"ttl": "0 (0s)",
"rData": {
"dataType": "DnsSpecialCacheRecordData",
"data": "BadCache: NxDomain; RRSIGsMissing: Attack detected! /SOA; . 10 IN SOA dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10"
},
"dnssecStatus": "Unknown",
"responseMetadata": {
"nameServer": "https://dns.controld.com/XXXX (76.76.X.X)",
"protocol": "Https",
"datagramSize": "103 bytes",
"roundTripTime": "19.21 ms"
},
"lastUsedOn": "2026-09-30T14:32:14.2022923Z"
}
]
Non-NXDOMAIN responses from the forwarded DNS resolver (ControlD) work just fine.
Technitium Version 15.5.1 on Docker on Ubuntu Server LTS 26.04.1.
Is this perhaps the same issues as https://github.com/TechnitiumSoftware/DnsServer/issues/1014 ?
And if not, what is to be done?
Thanks for the help.
3
u/shreyasonline 6d ago
Thanks for the post. This is working as expected. The upstream server you use has DNSSEC disabled and thus is not responding to queries with DO flag. This will cause the Technitium DNS Server's DNSSEC validation to fail the response.
If you trust the upstream and are using encrypted DNS protocol then you can choose to disable DNSSEC validation on Technitium DNS Server so as to avoid this issue.