J Doe <[email protected]> writes:

> Our mail server uses BIND and performs DNSSEC validation.  In the
> resolution logs, I noticed the following starting around May 6th:
>
> 09-May-2026 11:30:55.171 lame-servers: info: broken trust chain
> resolving 'mailchimp.com.dob.sibl.*support-intelligence.net*/A/IN':
> 38.130.107.118#53

Surely there are no asterisks in your log.  (I think it's better not to
add such markup.)

> AFAIK, this is a domain that is checked via a default install of
> SpamAssassin 4.0.2.>

egrep -R on my rules makes me lean that way.

> ** Is anyone else seeing this ?

If I run dig, I get a broken trust chain error in the log and SERVFAIL.

> ** Is there someway to get a hold of the people that run this domain
>    and notify them of their DNS issues ?

Back when I was young, there was a concept of a domain technical
contact.  I don't know if writing to those works, and how you'd do that
with borked DNS, but you could try.

Reply via email to