Incorrect DNS Resolution for archive.is / archive.ph
Hi, I'm experiencing incorrect DNS resolution for archive.is. Public discussions indicate this is due to the site operator intentionally returning bad IPs to resolvers that use EDNS, and my testing confirms this behaviour (it works via 1.1.1.1 but not NextDNS). Can you confirm this is the cause and advise if there's an official workaround NextDNS recommends?
Blocked out my public IP for obvious reasons.
From the router, from which these queries have been tested (which I can see in the NextDNS logs as shown above), shows this DIG response:
root@UCGF-ROUTER:~# dig archive.is
; <<>> DiG 9.16.50-Debian <<>> archive.is
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12564
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;archive.is. IN A
;; ANSWER SECTION:
archive.is. 31 IN A 31.133.0.117
;; Query time: 0 msec
;; SERVER: 127.0.0.1#53(127.0.0.1)
;; WHEN: Sat Jul 26 11:02:47 BST 2025
;; MSG SIZE rcvd: 55
If you go to 31.133.0.117, you will find the page I see below, which shows a Polish RPG gaming community.
Note, if I go to a full archive.is page, I will receive "ERR_SSL_UNRECOGNIZED_NAME_ALERT"
Can you help understand why NextDNS is serving me a false IP for archive.is? This is a well-known website. FYI, I've validated with several people, when they access archive.is they see the real page.
Final validation, I changed my DNS provider to simply `1.1.1.1` and the page again works fine.
All of this information should validate that the upstream (NextDNS) is the one providing bad answers.
Please help and or investigate.
Many thanks.
Note, I am a paying member. This isn't confidence-inspiring at all.
3 replies
-
Bump.
-
Bump
-
Bump. Someone from NextDNS must care, right... right?
Content aside
-
1
Votes
- yesterdayLast active
- 3Replies
- 64Views
-
1
Following