<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">Hi Jhonny,<div class=""><br class=""></div><div class="">It seems like you're looking at the wrong zone. The error you get, is about the reverse delegation of the 200.7.160.0/20 subnet.</div><div class=""><br class=""></div><div class="">You do have 200.7.160.0/24 correctly set up:</div><div class=""><br class=""></div><div class=""><div class=""> ❯ dig -x 200.7.160.0 soa @200.7.160.10 +norec</div><div class="">...</div><div class="">;; AUTHORITY SECTION:</div><div class="">160.7.200.in-addr.arpa.<span class="Apple-tab-span" style="white-space: pre;"> </span>3600<span class="Apple-tab-span" style="white-space: pre;"> </span>IN<span class="Apple-tab-span" style="white-space: pre;"> </span>SOA<span class="Apple-tab-span" style="white-space: pre;"> </span><b class=""><a href="http://marte.umsa.bo" class="">marte.umsa.bo</a>. <a href="http://root.umsa.bo" class="">root.umsa.bo</a>. 10101804 3600 7200 86400 86400</b></div><div class=""><br class=""></div><div class=""><br class=""></div><div class=""><br class=""></div><div class="">But not the other 15 /24 blocks in that /20:</div><div class=""><div class=""><br class=""></div><div class="">eg for 161.7.200.in-addr.arpa:</div><div class=""><br class=""></div><div class="">~ ❯ dig -x 200.7.161.0 soa @200.7.160.10 +norec</div><div class="">...</div><div class="">;; AUTHORITY SECTION:</div><div class="">161.7.200.in-addr.arpa.<span class="Apple-tab-span" style="white-space:pre"> </span>3600<span class="Apple-tab-span" style="white-space:pre"> </span>IN<span class="Apple-tab-span" style="white-space:pre"> </span>SOA<span class="Apple-tab-span" style="white-space:pre"> </span><b class="">a.misconfigured.dns.server.invalid. hostmaster.161.7.200.in-addr.arpa. 2022041104 10800 3600 604800 3600</b></div><div class=""><br class=""></div><div class=""><br class=""></div></div><div class="">or even worse for others:</div><div class=""><br class=""></div><div class=""><div class="">~ ❯ dig -x 200.7.171.0 soa @200.7.160.10 +norec</div><div class=""><br class=""></div><div class="">;; ->>HEADER<<- opcode: QUERY, status: <b class="">REFUSED</b>, id: 15315</div><div class="">;; flags: qr; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1</div><div class=""><br class=""></div><div class="">;; OPT PSEUDOSECTION:</div><div class="">; EDNS: version: 0, flags:; udp: 1232</div><div class="">;; QUESTION SECTION:</div><div class="">;0.171.7.200.in-addr.arpa.<span class="Apple-tab-span" style="white-space:pre"> </span>IN<span class="Apple-tab-span" style="white-space:pre"> </span>SOA</div><div class=""><br class=""></div></div><div class=""><br class=""></div><div class="">I would recommend adding the other in-addr.arpa zones, and trying again.</div><div class=""><br class=""></div><div class=""><br class=""></div><div class="">Cheers,</div><div class=""><br class=""></div><div class="">Frank</div><div class=""><br class=""></div><div class=""><div><br class=""><blockquote type="cite" class=""><div class="">On 10 May 2022, at 17:56, Jhonny Paco via Pdns-users <<a href="mailto:pdns-users@mailman.powerdns.com" class="">pdns-users@mailman.powerdns.com</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class="">Hi Jan-Piet<br class=""><br class="">Thank you for your attention, but my problem is with (Internet Addresses Registry for Latin America and the Caribbean) --> LACNIC (<a href="https://query.milacnic.lacnic.net/search?id=200.7.160.10" class="">https://query.milacnic.lacnic.net/search?id=200.7.160.10</a>) --> and their QREFUSED report.<br class=""><br class="">They are using automated tools to validate DIG answer and verify AUTHORITY SECTION detail.<br class=""><br class="">Question:<br class=""><br class="">Is it possible config PDNS server to show AUTHORITY SECTION?<br class=""><br class="">If not posible, exist another option to acomplish LACNIC request?<br class=""><br class="">It is my last email to day, no more...<br class=""><br class="">Best Regards<br class="">_______________________________________________<br class="">Pdns-users mailing list<br class=""><a href="mailto:Pdns-users@mailman.powerdns.com" class="">Pdns-users@mailman.powerdns.com</a><br class="">https://mailman.powerdns.com/mailman/listinfo/pdns-users<br class=""></div></div></blockquote></div><br class=""></div></div></body></html>