The register
Everything, in one list
Nineteen pieces, five sections, one page. This is the dense one on purpose.
| Piece | What it covers | Section |
|---|---|---|
| The question leaves, and does almost nothing on the way out | A query carries no route and no plan; everything that happens next is decided by the servers it meets. | Follow it down |
| Asked, and it declines to answer | A root server does not know the answer and is not supposed to; it knows who to ask next. | Follow it down |
| Another referral, one label further down | Each step resolves exactly one label, and the delegation chain is the only thing holding it together. | Follow it down |
| The one machine that actually holds the record | Authoritative means something narrow and specific, and confusing it with recursive is behind a surprising share of outages. | Follow it down |
| What a resolver is really doing | The recursive side keeps state, retries, and decides what to believe. | Follow it down |
| The countdown starts the moment you get the answer | TTL is not how long a record is valid — it is how long somebody else may keep serving the old one. | The countdown starts the moment you get the answer |
| Negative answers are cached too | The absence of a record is itself an answer with a lifetime, and it is the one people forget. | The countdown starts the moment you get the answer |
| Lowering the TTL before you move anything | The standard preparation for a migration, and why it has to happen a day early. | The countdown starts the moment you get the answer |
| Thirteen addresses, hundreds of sites | There are thirteen root addresses because of a packet size limit, and far more than thirteen machines because of anycast. | Thirteen addresses, hundreds of sites |
| What anycast actually does | The same address announced from many places, and the routing table deciding which one you reach. | Thirteen addresses, hundreds of sites |
| The root zone, and who signs it | The file itself is small, published, and signed in a ceremony that is a matter of record. | Thirteen addresses, hundreds of sites |
| Five servers, and what each was built to be good at | BIND, NSD, Knot, Unbound and PowerDNS solve overlapping problems with different priorities, and the differences are architectural. | Five servers, and what each was built to be good at |
| tinydns, and the file it answers from | The design that gives this domain its name answered from a single prebuilt constant database and refused to recurse in the same process. | Five servers, and what each was built to be good at |
| Why the two jobs were split apart | Keeping authoritative service and recursion in separate processes removed a whole class of failure, and the field eventually agreed. | Five servers, and what each was built to be good at |
| What DNSSEC does, and what it does not | It proves an answer came from the zone; it does not make the answer private or the zone correct. | Five servers, and what each was built to be good at |
| Lame delegation | A parent points at a server that will not answer for the zone, and everything below it goes quiet. | Where it actually breaks |
| Missing glue | When the nameserver lives inside the zone it serves, the parent has to carry its address or the chain cannot start. | Where it actually breaks |
| The serial that never incremented | Secondaries only pull when the number goes up, so an edit that forgets it never leaves the primary. | Where it actually breaks |
| Expired at the registrar | The commonest total outage has nothing to do with the servers at all. | Where it actually breaks |