Looks good to me.
You're wrong. His DNS is scrogged beyond usefulness, at this instant. no NS, no MX, bad SOA, no authoritative answsers.
Also, he can't receive mail now. My private mail to him with DNS Expert report has bounced 3 times, unknown user. At this instant, his DNS PA-NS-01.proassistinc.com is not even returning MX records. Here's his entire zone:
# dig @PA-NS-01.proassistinc.com proassistinc.com axfr
; <<>> DiG 8.2 <<>> @PA-NS-01.proassistinc.com proassistinc.com axfr
; (1 server found)
$ORIGIN proassistinc.com.
@ 1H IN SOA pa-ns-01. administrator (
122 ; serial
15M ; refresh
10M ; retry
1D ; expiry
1H ) ; minimum
1H IN A 216.9.233.130
1H IN HINFO "Intel" "Windows 2000"
cal 1H IN A 216.9.234.12
mail 1H IN A 216.9.234.41
www 1H IN A 216.9.233.130
@ 1H IN SOA pa-ns-01. administrator (
122 ; serial
15M ; refresh
10M ; retry
1D ; expiry
1H ) ; minimum
oops: no MX, no NS, busted SOA. "Looks bad to me"
When you do the other domains, look in %systemroot\system32\dns and you'll find the file for this domain. Simply copy it for the next domain using the file naming convention you'll see. Then edit the new file with UltraEdit32 or notepad. Save it again and again for each domain. Now when you run the New Zone wizard you will tell it to use an existing file and be finished much faster than filling out each domain via the wizard.
And, don't try to lose the trailing '.' on the NS records as Len suggested. Win2K doesn't work that way.
yes, W2K does work that way. I bet that W2K DNS writes text zone files that are BIND compatible, just like MS NT4 DNS does. why would that be?
Here's the output from your very own beloved NT4 SP6a nslookup:
C:\>nslookup
Serveur par d�faut : ns1.meiway.com
Address: 212.73.210.69
> set type=soa
> proassistinc.com
Serveur: ns1.meiway.com
Address: 212.73.210.69
R�ponse de source secondaire :
proassistinc.com
primary name server = pa-ns-01
responsible mail addr = administrator.proassistinc.com
serial = 122
refresh = 900 (15 mins)
retry = 600 (10 mins)
expire = 86400 (1 day)
default TTL = 3600 (1 hour)
proassistinc.com nameserver = PA-NS-01.proassistinc.com
proassistinc.com nameserver = PA-NS-02.proassistinc.com
PA-NS-01.proassistinc.com internet address = 216.9.234.11
PA-NS-02.proassistinc.com internet address = 216.9.234.12
Look at his "primary name server = pa-ns-01" it's a busted SOA. authoritative answer impossible.
The NS listing is my nameserver getting those glue records from the roots or my ns's cache, NOT from his DNS. His DNS is not returning any NS records at this instant.
Here's what I get using NetScan Tools:
Looking up [proassistinc.com]
Server: ns1.ttiweb.com
There's your mistake, Fravistat, if you want to help him with his DNS, you have to query right @ his DNS, like I do with dig and NetScanTools, and NOT using your ttiweb or fravistat DNS:
# dig @PA-NS-01.proassistinc.com proassistinc.com ns
; <<>> DiG 8.2 <<>> @PA-NS-01.proassistinc.com proassistinc.com ns
; (1 server found)
;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
;; QUERY SECTION:
;; proassistinc.com, type = NS, class = IN
;; AUTHORITY SECTION:
proassistinc.com. 1H IN SOA pa-ns-01. administrator.proassistinc.com. (
122 ; serial
15M ; refresh
10M ; retry
1D ; expiry
1H ) ; minimum
He's screwed his ns records for proassistinc.com zone and so his own NS, the one we're trying to help him with, is not even listing NS records. Your DNS is showing you his NS glue records from the root-servers, not the NS records from his NS.
Fravistat, I suggest you :
1. figure out how to make your own DNS answer authoritatively for fravistat.com and then, maybe, your DNS advice will be more accurate and credible.
btw, if you send me your fravistat W2K DNS zone file, I can see if it really is BIND compatible AND fix it for you so your DNS will answer authoritatively.
2. figure out how use NetScanTools. It's a GUI pgm so it "should" be very easy for you, but I'll give you a BIG HINT, for NST4:
Under the "namesever lookup" tab, click the "adv query setup" button and enter his ns as the ns to query. Then you'll start to see his DNS pb's, and maybe have at least the tiniest chance of giving him accurate advice, if his DNS's are even reachable, because for me at this instant, they aren't.
btw, my NST4, used correctly, and my dig agree on the state of his DNS.
btw, my NST4 agrees with my dig about YOUR DNS: it's not authoritatively answering for fravistat.com:
Looking up [fravistat.com]
Server: ns1.fravistat.com
Address: 216.144.135.194
res_mkquery(0, fravistat.com, 1, 2)
HEADER:
QUESTIONS:
------------
fravistat.com
fravistat.com
fravistat.com
fravistat.com
ns1.fravistat.com
ns1.ttiweb.com
[End Query]
==========
Len
