DNS

DNS 9 NOTAUTH vs 11 DSOTYPENI

Both DNS 9 (NOTAUTH) and 11 (DSOTYPENI) belong to the DNS Response Codes (RCODEs) category. 9 indicates that server Not Authoritative for zone, or Not Authorized. The server is not authoritative for the zone named in the Zone section. Meanwhile, 11 means that dSO-TYPE Not Implemented. The DNS Stateful Operations (DSO) type in the request is not supported by the server.

Description

Server Not Authoritative for zone, or Not Authorized. The server is not authoritative for the zone named in the Zone section.

When You See It

You sent a dynamic update or zone operation to a server that is not the authoritative master for that zone, or the server rejected it due to TSIG authentication failure.

How to Fix

Send the update to the correct primary authoritative server for the zone. If using TSIG, verify the key name and secret match on both client and server.

Description

DSO-TYPE Not Implemented. The DNS Stateful Operations (DSO) type in the request is not supported by the server.

When You See It

Your client attempted a DSO operation (like a keepalive or push subscription) that the server does not recognize or has not implemented.

How to Fix

Verify that both client and server support the same DSO-TYPE. Upgrade the server software or fall back to traditional DNS queries.

Key Differences

1.

DNS 9: Server Not Authoritative for zone, or Not Authorized. The server is not authoritative for the zone named in the Zone section.

2.

DNS 11: DSO-TYPE Not Implemented. The DNS Stateful Operations (DSO) type in the request is not supported by the server.

3.

You encounter 9 when you sent a dynamic update or zone operation to a server that is not the authoritative master for that zone, or the server rejected it due to TSIG authentication failure.

4.

You encounter 11 when your client attempted a DSO operation (like a keepalive or push subscription) that the server does not recognize or has not implemented.

When to Use Which

For 9 (NOTAUTH): Send the update to the correct primary authoritative server for the zone. If using TSIG, verify the key name and secret match on both client and server. For 11 (DSOTYPENI): Verify that both client and server support the same DSO-TYPE. Upgrade the server software or fall back to traditional DNS queries.

Learn More