Asked, and it declines to answer
The root does not hold the record. It holds the map to the next person who might.

What the root actually sends back
When a recursive resolver fires its first query for an unknown name — say, www.example.com, type A — the root server receives a question it could answer with either a referral or an error. It returns a referral, though not quite in the shape people expect. What it returns is a negative answer in a very specific shape: a NOERROR response with no records in the Answer section, and a populated Authority section pointing at the com TLD nameservers, plus glue in the Additional section to make those addresses reachable without a separate lookup. That structure — NOERROR, empty answer, referral — is often mistaken for a failure. It is the system working exactly as designed.
The response code is crucial. A root server does not return NXDOMAIN for a name below the root zone, because doing so would be a lie: it genuinely does not know whether www.example.com exists, only that the answer lives under .com. Returning NXDOMAIN here would poison every cache downstream for the length of the SOA's negative TTL, ending the lookup before it started. NOERROR with a referral says, precisely, I do not have authority past this point; go here.

The protocol shape of "not my job"
The mechanics are defined in RFC 1034 ↗, which describes name server operation and the delegation model that the IANA root zone implements. A delegation is nothing more than an NS record set in the zone, owned by the parent but pointing at the child. The root zone contains NS records for every TLD — .com, .de, .org, .museum, all of them — and the root servers are authoritative for those NS records. They are not authoritative for anything inside .com. That boundary is the entire point.
Glue records enforce the mechanic. If the delegated nameserver's own name falls within the zone being delegated — the classic in-bailiwick case — then reaching it would require resolving a name that itself needs a referral, creating a loop. The parent breaks the loop by carrying address records for those servers in the same response, in the Additional section, so the resolver can move on without another query. The root zone carries glue for every TLD nameserver whose name ends in the TLD it serves. You can inspect the root zone file directly at https://www.internic.net/domain/root.zone ↗ — it is a plain text file, published daily, and the glue records are plainly visible.
What the root server absolutely does not do is recurse. A root server runs authoritative software — NSD from NLnet Labs, or BIND from ISC, or others configured to answer only for the zones they are loaded with. They carry no cache, perform no iteration, and follow no referrals. When the response leaves the root, it is the resolver's job to take that referral and repeat the process one label further down.
Where the silent no goes wrong
The failure mode is quiet. A misconfigured root hint — a resolver's internal list of root server addresses — means the resolver may be querying a machine that has stopped answering, and the referral never arrives. The resolver times out and retries, working through the thirteen root addresses until it gets a response. Because the root operates via anycast, each of those thirteen addresses reaches one of many physical nodes worldwide, and a node going dark typically causes a timeout rather than an error — the routing withdraws and the next node picks up, but there may be a window.
The other failure mode belongs to operators who confuse referral with refusal. A resolver log showing many NOERROR responses with empty answer sections from root servers is not evidence of a problem; it is evidence of a working delegation chain. The issue arises only if the Authority section is also empty — a root server sending NOERROR with nothing in either Answer or Authority — which would indicate a misconfiguration on the root side serious enough to make news. What operators actually see, almost every time, is the expected referral structure being correctly forwarded to the TLD, then onward to the authoritative server that genuinely holds the record.
The root declines because it was built to decline. That is not a limitation of the system; it is the architecture.
A misconfigured root hint — a resolver's internal list of root server addresses — means the resolver may be querying a machine that has stopped answering, and the referral never arrives.

Returning NXDOMAIN here would poison every cache downstream for the length of the SOA's negative TTL, ending the lookup before it started.