stub-zone not returning A record for cname

W.C.A. Wijngaards wouter at
Fri Feb 9 16:09:04 UTC 2018

Hi Joe,

On 05/02/18 14:05, Joe via Unbound-users wrote:
> Hi list
> I have a stub-zone entry like the following:
> stub-zone:
>         name: "office.intra"
>         stub-addr:
>         stub-addr:
> This works great except for CNAME entries, where I get the CNAME but not
> the A Record.
> $ dig
> ...
>    3494    IN    CNAME    test.manage.intra.
> .            3494    IN    SOA
> 2018020500 1800 900 604800 86400
> The manage.intra zone is configured as local-zone on unbound.
> I am able to query the manage.intra zone:
> $ dig test.manage.intra.
> test.manage.intra.    60    IN    A
> What am I missing?

Unbound works by first checking local-zones, then cache, then performing
recursive lookup, that recursive lookup then uses the cache and sends
queries to upstream authority servers.

The localzones are a filter in front of all other stuff that unbound
does.  Unbound wants to lookup manage.intra at the back, so it needs a
forward-zone or a stub-zone for that, somewhere where it can find the
information in manage.intra.

With (not yet released) authority zones you can do this, and configure
unbound to use that authority zone data as a proxy for upstream queries.
 Instead of sending queries to upstream servers, it'll use that
authority data directly.  I.e. it'll sit at the back, instead of as
local-zones at the front.  There is also an option to put auth-zones at
the front.  And another one to failover to normal internet queries on
validation failures (for RFC7706 root zone copies).  If enabled as a
proxy for upstream queries, unbound would use it to answer queries there
but also CNAMEs pointing there.

Best regards, Wouter

> Best regards and thanks
> Joe

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <>

More information about the Unbound-users mailing list