On Wed, Jun 17, 2026 at 11:55:04AM +0200, Patrick Ben Koetter via Postfix-users
wrote:
> list.sys4.de has valid PTRs for it's A and AAAA record:
>
> $ dig +short -x 2a03:4000:20:189::195
> list.sys4.de.
> ...
> $ dig -x 45.90.5.195
> 195.5.90.45.in-addr.arpa. 43200 IN PTR list.sys4.de.
Indeed the DNS records are fine, from all relevant nameservers:
https://dnsviz.net/d/list.sys4.de/ajTHmw/dnssec/
https://dnsviz.net/d/195.5.90.45.in-addr.arpa/ajKbmw/dnssec/
https://dnsviz.net/d/5.9.1.0.0.0.0.0.0.0.0.0.0.0.0.0.9.8.1.0.0.2.0.0.0.0.0.4.3.0.a.2.ip6.arpa/ajTJ9g/dnssec/
The only technical anomaly is not known to be a problem in reality, the
sys4.de DNSKEY RRset includes a spurious ECDSA P256(13) ZSK, with no
associated RRSIGs. Since there's no ECDSA P256 DS record, no known
validator will ignore the RSA RRSIGs and require ECDSA, but that
ZSK should be dropped.
Whatever problem the OP is having with the list server's DNS is on
the OP's end.
--
Viktor. 🇺🇦 Слава Україні!
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]