Uploaded image for project: 'Atlassian Guard'
  1. Atlassian Guard
  2. ACCESS-1138

Domain Verifications Fails if Too many TXT records in DNS

      Issue Summary

      If DNS contains a large number of unique TXT record items in the root of the domain (including the Atlassian Verification), the Domain cannot be verified or re-verified during the normal checks.

      Steps to Reproduce

      1. set up 30 TXT record entries with a lot of text in them
      2. Wait for the changes to propagate to our system. Please note that the change may take up to 72 hours for our system to stop caching the old results.
      3. Attempt to claim the domain (or reclaim it)

      Expected Results

      The domain claims as expected

      Actual Results

      The domain claim fails and the following error is thrown in the logs:
      Error: queryTxt ESERVFAIL EXAMPLE.com at QueryReqWrap.onresolve [as oncomplete] (dns.js:213:19)

      Notes

      Domain Verification is checked on standard DNS (not EDNS) and if the Message Size is greater than 512 bytes for TXT Records, the verification can fail

      Workaround

      Currently, there are only two methods that can be used to bypass this issue:
      1. Delete some of the TXT record entries so that the message size is less than 512 bytes
      2. Use HTTPS verification instead.

          Form Name

            [ACCESS-1138] Domain Verifications Fails if Too many TXT records in DNS

              gmoir Geoff
              jlong@atlassian.com Jared Long
              Affected customers:
              7 This affects my team
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: