I’m trying to help the company who (not surprisingly) had DNS issues last week, and the setup seems odd (the 20s TTL seems wrong to me as well).

This was just the first time I’ve seen a setup where you could get another Authority response when asking for an A record (i.e. after doing the NS lookups, and being told who should be the authority for that domain).

> I guess your concern is that a DNS server that should be authoritative for the domain isn’t returning an answer.
> However, what it is returning (an Authority section) is exactly what both the root and .com DNS servers returned. Therefore the client will simply carry on following the chain and ask one of the servers in the authority section, which as you noted works fine (on OS X I didn’t need the +noedns flag).
> So it’s slightly odd, but it’s all within spec. Of more concern is the 20s TTL, which is insanely low. Whatever you’re doing that requires that low a TTL, do it another way, cos that’s not really how DNS is meant to work :)
