anynode SBC fails to resolve sip.pstnhub.microsoft.com (DNS)

SBC integration errorsMANUAL FIX INSIDEFREE — NO SIGNUP
Quick answer. sip.pstnhub.microsoft.com returns multiple A records per region with a real TTL, and anynode resolves it at registration time; a stale or broken resolver on the VM makes that lookup fail intermittently. The two usual root causes on Azure VMs: systemd-resolved caching a stale record past its TTL (often after a Microsoft regional rotation), and an IPv6-first resolver with no working IPv6 route, which makes every lookup time out before falling back to IPv4. The fix is to flush the local cache, verify the lookup resolves cleanly with dig, and pin IPv4 (or fix the v6 route) so anynode's resolver returns instantly.

The raw code check

Run this before you change anything — it confirms the root cause in one pass:

lookup — cached/broken resolverFAIL
$ dig +short sip.pstnhub.microsoft.com
;; no answer — SERVFAIL after 5.0s
$ resolvectl statistics
Current Cache Size: 312 (stale beyond TTL)
lookup — after flush + IPv4 pinOK
$ dig +short sip.pstnhub.microsoft.com
52.112.0.0/14 region answers — 2 A records, TTL 3600
$ resolvectl statistics
Current Cache Size: 4 (within TTL)

The manual fix — 3 steps

  1. Flush the VM resolver cache. On the Azure VM hosting anynode, run: sudo resolvectl flush-caches (older images: sudo systemd-resolve --flush-caches). This drops every cached record so the next lookup hits the real resolver.
  2. Verify the lookup is clean and in-TTL. Run dig +short sip.pstnhub.microsoft.com — you should get the regional A records in well under a second. Then re-check resolvectl statistics: the cache should be small and refreshing within the record's TTL, not pinning a 312-record stale pile.
  3. Pin IPv4 or fix the IPv6 route. If lookups are slow-but-succeeding, the resolver is almost certainly trying IPv6 first. Either give the VNet a working IPv6 route, or remove the v6 resolver from /etc/resolv.conf (and set anynode's SIP DNS to the IPv4 resolver). Then restart anynode's registration and watch it settle.

The automated alternative

If you'd rather never do this again: VoipFlow runs this whole class of maintenance as software — certificate issue-and-bind in about 12 seconds, signaling on port 5062 so SIP ALG rewriting never engages, per-tenant isolation, flat $399/mo. The 14-day sandbox is free, no credit card, and no sales follow-up unless you ask for one.

Deploy Free 14-Day Sandbox — No Credit Card Required

Related