TinyDNS tinydns.org

How DNS resolves a name, and how the servers that do it are run.

The register

Everything, in one list

Nineteen pieces, five sections, one page. This is the dense one on purpose.

Every piece on the site
PieceWhat it coversSection
The question leaves, and does almost nothing on the way outA query carries no route and no plan; everything that happens next is decided by the servers it meets.Follow it down
Asked, and it declines to answerA root server does not know the answer and is not supposed to; it knows who to ask next.Follow it down
Another referral, one label further downEach step resolves exactly one label, and the delegation chain is the only thing holding it together.Follow it down
The one machine that actually holds the recordAuthoritative means something narrow and specific, and confusing it with recursive is behind a surprising share of outages.Follow it down
What a resolver is really doingThe recursive side keeps state, retries, and decides what to believe.Follow it down
The countdown starts the moment you get the answerTTL is not how long a record is valid — it is how long somebody else may keep serving the old one.The countdown starts the moment you get the answer
Negative answers are cached tooThe absence of a record is itself an answer with a lifetime, and it is the one people forget.The countdown starts the moment you get the answer
Lowering the TTL before you move anythingThe standard preparation for a migration, and why it has to happen a day early.The countdown starts the moment you get the answer
Thirteen addresses, hundreds of sitesThere are thirteen root addresses because of a packet size limit, and far more than thirteen machines because of anycast.Thirteen addresses, hundreds of sites
What anycast actually doesThe same address announced from many places, and the routing table deciding which one you reach.Thirteen addresses, hundreds of sites
The root zone, and who signs itThe file itself is small, published, and signed in a ceremony that is a matter of record.Thirteen addresses, hundreds of sites
Five servers, and what each was built to be good atBIND, NSD, Knot, Unbound and PowerDNS solve overlapping problems with different priorities, and the differences are architectural.Five servers, and what each was built to be good at
tinydns, and the file it answers fromThe design that gives this domain its name answered from a single prebuilt constant database and refused to recurse in the same process.Five servers, and what each was built to be good at
Why the two jobs were split apartKeeping authoritative service and recursion in separate processes removed a whole class of failure, and the field eventually agreed.Five servers, and what each was built to be good at
What DNSSEC does, and what it does notIt proves an answer came from the zone; it does not make the answer private or the zone correct.Five servers, and what each was built to be good at
Lame delegationA parent points at a server that will not answer for the zone, and everything below it goes quiet.Where it actually breaks
Missing glueWhen the nameserver lives inside the zone it serves, the parent has to carry its address or the chain cannot start.Where it actually breaks
The serial that never incrementedSecondaries only pull when the number goes up, so an edit that forgets it never leaves the primary.Where it actually breaks
Expired at the registrarThe commonest total outage has nothing to do with the servers at all.Where it actually breaks