Five servers, and what each was built to be good at
Why the two jobs were split apart

One server doing two things at once
For most of DNS's early life, the same process answered both kinds of question: it resolved names on behalf of clients, and it held authoritative data for zones it was responsible for. BIND, which ISC has maintained since the 1990s, shipped this way by default. A single named instance would recurse for your LAN, serve your zone files, and manage its own cache — all from one configuration block. The convenience was obvious. The failure surface, less so.
The problem is that the two jobs have almost nothing in common beyond the protocol. An authoritative server's contract is narrow: receive a question about a name in a zone it holds, return the data exactly as written. A recursive resolver's contract is the opposite of narrow — it must chase referrals across an arbitrary number of delegations, cache results from strangers, and decide what to believe. Combining them means that cache state and authoritative state share process memory, and that a cache-poisoning attack has a straight path to authoritative data. It also means that a resource-exhaustion attack against the resolver — a flood of expensive recursive queries — can starve legitimate queries to the authoritative zone.
The logic for splitting the roles appeared early in the literature and was articulated sharply in D. J. Bernstein ↗'s djbdns design. Bernstein separated the authoritative server (tinydns) from the recursive resolver (dnscache) into processes that did not share state at all — they ran as different binaries, under different UIDs, with no communication between them. The attack surface shrank by construction: tinydns answered no recursive queries, and dnscache held no authoritative records that could be contaminated. Whether or not any given operator uses djbdns, that architecture became the model the field converged toward.

How the field converged
NLnet Labs' Unbound, released in 2008, was from the start a resolver only — authoritative service was explicitly out of scope. NSD, also from NLnet Labs, is the mirror image: authoritative only, no recursion, no cache. Operators who need both functions run both processes, typically on separate machines. CZ.NIC's Knot DNS follows the same discipline: Knot Resolver is a separate codebase from Knot DNS, and the project treats the split not as a limitation but as a design statement.
BIND did eventually introduce a measure of separation through its view system, and later work hardened the boundary between its recursive and authoritative paths. PowerDNS, maintained by the company of the same name, ships as two distinct daemons — Recursor and Authoritative Server — that can communicate but do not merge state. The trend line across every major implementation is the same: the combined mode that was once the default is now either deprecated, discouraged, or structurally prevented. RFC 5358 ↗, published in 2008, addressed the amplification risk of open resolvers and pointed toward the same conclusion from a security angle: a server answering recursive queries for the public internet is a different beast from one serving authoritative data, and they should not be the same beast.
The operational gains compound. An authoritative server that does no recursion can have its access list set to "the whole internet" without becoming an amplifier. A resolver that holds no authoritative records cannot be induced to return poisoned data to everyone who asks for that zone. Capacity planning becomes meaningful: authoritative query rates reflect your delegation traffic, recursive query rates reflect your user load, and neither obscures the other. TTL tuning and negative caching behave predictably on the resolver, because the resolver is not simultaneously trying to answer from its own authoritative data.
The split also makes DNSSEC validation tractable. A resolver that validates can do so without worrying about the authority of its own zone data muddying the chain of trust. The authoritative side signs; the recursive side verifies. The roles reinforce each other precisely because they are separated.
What the field learned, slowly, is that convenience in configuration is a form of hidden complexity in operation. Two processes you understand are safer than one process you only mostly understand.
A recursive resolver's contract is the opposite of narrow — it must chase referrals across an arbitrary number of delegations, cache results from strangers, and decide what to believe.

It also means that a resource-exhaustion attack against the resolver — a flood of expensive recursive queries — can starve legitimate queries to the authoritative zone.