Stale DNS cache after change
Resolvers still serve prior answers after an authoritative change because TTL has not expired.
Problem summary
Resolvers still serve prior answers after an authoritative change because TTL has not expired.
Symptoms
- Some networks see old records while others see new ones
- Cutover appears incomplete for longer than expected
Possible causes
- Misconfiguration
- Incomplete rollout
- DNS propagation delay
How to diagnose
- Confirm the symptom in headers or reports
- Inspect the relevant DNS records
- Validate with a trusted checker
How to fix
- Correct the DNS or signing configuration
- Re-test and confirm alignment where required
How to verify
- Re-check DNS
- Send a test message
- Confirm expected authentication results
Prevention
- Document changes
- Monitor reports after deployment
When to escalate
- Production mail is failing authentication after a change window