NS-C: where the third nameserver answers from
Task Q4 resolver follow-up to DNS-2026-0907-2 · Author network maintenance, badge 441902-7, the crew that carries the register and does not interpret it · Method three probes, three different nights, one variable at a time. I do not run transfers. The other crew already did that.
The delegation is on the record: fen.internal says it has three nameservers,
and the third, ns-c.fen.internal, has no address anywhere and answers nothing
when you ask it directly (axfr-from-53). A name with
no address cannot be answered for. My trade is the other half of that sentence:
if an answer ever does come, it comes from somewhere, and somewhere is a port,
and a port is in my register. I was asked to find the port. I have not. I have
found the minute.
Probe 1 — daylight, the change host
2026-09-03, 09:02, from the host change work runs off. Delegation only, three retries, UDP then a TCP transfer attempt that was open eleven seconds and then was not open. In the same minute I walked the maintenance VLAN: the address block was pulled in 2023, the switch still carries the VLAN, and the whole /29 is unassigned. It is still cabled because my supervisor says infrastructure you do not use is still infrastructure. That is exactly the kind of sentence I am allowed to write down.
Probe 2 — 03:17:09, from a host on that VLAN
Not cleverness. Insomnia and a laptop. On the night of the third, at 03:17:09, from a maintenance host:
; <<>> ns-c.fen.internal. 3600 IN A 192.0.2.61
;; QUESTION SECTION:
;ns-c.fen.internal. IN A
;; WHEN: Wed Sep 03 03:17:09 2026
;; MSG SIZE rcvd: 61The TTL on the answer is 3,600, which is what the resolver's default is, and the TTL on the delegation above it is 3,600, which is nothing: the answer carried a number, not a fact. I asked twice more inside the minute. It answered twice. At 03:17:59 I asked; delegation only. At 03:18:09, the same host, the same command: delegation only. Every night since, at any other minute I have tried, from that host and eleven others, the name answers nothing, which is what it always did.
192.0.2.61 is the address the zone hands over first among the five the
primary denies, for a scheduler that went to the recycler
(axfr-from-53). My register names the recycler run,
the date, the hauler. The hardware in that manifest cannot be standing in my
row. The maintenance switch had no MAC in its table for the address at 03:15,
at 03:17, or at 03:20 — I pulled the polls myself — and the frame arrived
anyway, which my tools do not have a field for.
Probe 3 — daylight, the VPN
It is not allowed and I did it anyway, from home, 21:40, asking a question my own supervisor told me not to ask. Delegation only, twice. I am reporting that it refused me as much as I am reporting that something answered the maintenance host at 03:17:09. I read the two facts as one fact. It is the shape of the circuit from circuit-9-12: twenty-two metres longer than its own route, carrying nothing, answering when you stand at the end that is not there.
Disposition
No resolver on the estate changes on my word. The delegation stays as the zone
believes it. Q4 line goes in as it always goes in: two servers answer for
fen.internal. What I am filing is one address, one minute, and which
machines are in the room. If a second crew wants to repeat this, my badge
number is on the ticket, which is the whole point of a number.
— net-maint-7, badge 441902-7
Related: axfr-from-53, circuit-9-12, the-fourth-nameserver, hesper-04, index.