Re: [exim] DANE ERROR: TLSA LOOKUP DEFER

Top Page
Delete this message
Reply to this message
Author: daniel
Date:  
To: Exim-users
Old-Topics: Re: [exim] DANE ERROR: TLSA LOOKUP DEFER
Subject: Re: [exim] DANE ERROR: TLSA LOOKUP DEFER
Hello,

I have an update of this problem.

Today I found out the solution of this problem.

The solution is to NOT using any google DNS server (8.8.8.8 8.8.4.4).

I am not sure how these two things does not work to each other; But once
i switch to not using it, for example, use 1.1.1.1 instead, it INSTANTLY

 works again.

Thank you.


On 2020/3/30 下午 07:34, Phil Pennock wrote:
> On 2020-03-25 at 13:10 -0400, Phil Pennock via Exim-users wrote:
>> On 2020-03-23 at 20:54 +0800, daniel via Exim-users wrote:
>>> We recently received many of our end users complains that they are having problem sending email to *.gov.hk with this exim error:
>>> DANE ERROR: TLSA LOOKUP DEFER
>> Their DNS is broken.
> For clarity: I did not look at any DNS records before making that
> statement, it was my short-form explanation of what the error message
> means in practice.
>
> 95+% of the time, it means "they have DNS servers which don't reply when
> asked for TLSA records".
>
> To get more details out of Exim, run with `-d+transport+dns` to get
> debugging, enabling additional debug content in the "transport" and
> "dns" areas.
>
> -Phil