Browse
Five sections, nineteen pieces, and no dropdown to fight
Everything on the site, grouped the way it was written.
Follow it down
Root to answer, one referral at a time.
- 01The question leaves, and does almost nothing on the way outA query carries no route and no plan; everything that happens next is decided by the servers it meets.
- 02Asked, and it declines to answerA root server does not know the answer and is not supposed to; it knows who to ask next.
- 03Another referral, one label further downEach step resolves exactly one label, and the delegation chain is the only thing holding it together.
- 04The one machine that actually holds the recordAuthoritative means something narrow and specific, and confusing it with recursive is behind a surprising share of outages.
- 05What a resolver is really doingThe recursive side keeps state, retries, and decides what to believe.
The countdown starts the moment you get the answer
TTL, caching, and what is still being served.
- 01The countdown starts the moment you get the answerTTL is not how long a record is valid — it is how long somebody else may keep serving the old one.
- 02Negative answers are cached tooThe absence of a record is itself an answer with a lifetime, and it is the one people forget.
- 03Lowering the TTL before you move anythingThe standard preparation for a migration, and why it has to happen a day early.
Thirteen addresses, hundreds of sites
Anycast, and what the root actually is.
- 01Thirteen addresses, hundreds of sitesThere are thirteen root addresses because of a packet size limit, and far more than thirteen machines because of anycast.
- 02What anycast actually doesThe same address announced from many places, and the routing table deciding which one you reach.
- 03The root zone, and who signs itThe file itself is small, published, and signed in a ceremony that is a matter of record.
Five servers, and what each was built to be good at
The implementations, compared honestly.
- 01Five servers, and what each was built to be good atBIND, NSD, Knot, Unbound and PowerDNS solve overlapping problems with different priorities, and the differences are architectural.
- 02tinydns, and the file it answers fromThe design that gives this domain its name answered from a single prebuilt constant database and refused to recurse in the same process.
- 03Why the two jobs were split apartKeeping authoritative service and recursion in separate processes removed a whole class of failure, and the field eventually agreed.
- 04What DNSSEC does, and what it does notIt proves an answer came from the zone; it does not make the answer private or the zone correct.
Where it actually breaks
The misconfigurations behind real outages.
- 01Lame delegationA parent points at a server that will not answer for the zone, and everything below it goes quiet.
- 02Missing glueWhen the nameserver lives inside the zone it serves, the parent has to carry its address or the chain cannot start.
- 03The serial that never incrementedSecondaries only pull when the number goes up, so an edit that forgets it never leaves the primary.
- 04Expired at the registrarThe commonest total outage has nothing to do with the servers at all.