SERVFAIL with deutsche-glasfaser.de

That looks ok.

This isn't a Pi-hole issue, so our support will be limited as we are leaving our immediate area of expertise - SERVFAIL issues are both common and expected but also hard to troubleshoot when occuring persistently.

It doesn't seem to be a general issue with unbound's configuration either, as your observation seems limited to a select few domains.

So yery likely, your observation is caused by some misconfiguration within the scope of authoritative DNS servers that unbound is communicating or trying to communicate with, or something upstream is messing with DNS requests.

In the past, we've had a few reports where a 'security' feature from an ISP's network blocked access to certain IPs, see Pi-hole unbound servfail - #16 by deHakkelaar.
On one instance, deHakkelaar provided a script to facilitate trouble-shooting an unbound issue - see Need help and techniques to debug DNS failure on Facebook and Instagram using Pihole with Unbound - #31 by deHakkelaar.
However, that seems to rely on some log files produced somewhere along that conversation.
Maybe @deHakkelaar would be able to explain what is needed.

1 Like