After some further research, we’re still pretty confident that any DNS issues that are being experienced are not on our end. From everything we can see, our DNS servers are all responding properly and are returning the proper IP addresses for our gateways.
A recent DNS cache poisoning vulnerability was announced in the last few weeks, and there are reports of it being exploited in the wild. US-CERT VU#800113 contains details of the vulnerability. We do not know whether this may be impacting certain ISPs DNS servers, but it is a supposition based on the evidence we have available to us at this time.
To show that our DNS is working properly, we’ve used DNS Stuff to compile a report for each of our gateways showing that all the root DNS servers list our DNS servers as authoritative and that each of our DNS servers is returning the proper response for our gateway addresses. Click the link for each gateway to see the report. You can use this report when talking with an ISP about them resolving the issue.
MF1
MF2
G1
G2