skip to content

What do the DNS response codes NOERROR, NXDOMAIN, SERVFAIL and REFUSED mean, and how does a NODATA answer differ from NXDOMAIN?

level: middleimportance: must knowfreq 48%

answer

  1. a 4-bit field in the header
  2. missing name versus missing type
  3. a pseudo rcode you have to infer
  4. failure says nothing about existence
  5. policy, not absence

basics

~20 s

NOERROR (0) is success, NXDOMAIN (3) says the name does not exist, SERVFAIL (2) that the server could not answer, REFUSED (5) a policy refusal. NODATA is not an rcode: NOERROR with an empty answer, so the name exists without that type.

solid answer

~50 s

The rcode is the 4-bit `RCODE` field of the DNS header (RFC 1035 section 4.1.1). `NOERROR` (0) means the query was processed. `NXDOMAIN` (3), the old "Name Error", means the queried name does not exist for any type, and RFC 8020 adds that nothing below it exists either. `SERVFAIL` (2) means the server could not produce an answer; for a recursive resolver that usually means the authoritative servers were unreachable or broken, or DNSSEC validation failed, so it says nothing about whether the name exists. `REFUSED` (5) is a policy decision, such as a resolver declining clients it does not serve. `NODATA` is a pseudo-rcode from RFC 2308: `NOERROR` with an empty answer section and usually the zone's `SOA` in the authority section, meaning the name exists but has no record of the requested type.

code

dns · 11 lines
dns
; Query: www.example.com. IN AAAA  (name has only an A record)
; Header: QR=1 AA=1 RCODE=NOERROR  ANCOUNT=0 NSCOUNT=1   -> NODATA
; ANSWER: (empty)
; AUTHORITY:
example.com.  3600  IN  SOA  ns1.example.com. hostmaster.example.com. 2026093001 7200 900 1209600 300

; Query: wwww.example.com. IN A  (name does not exist)
; Header: QR=1 AA=1 RCODE=NXDOMAIN ANCOUNT=0 NSCOUNT=1   -> NXDOMAIN
; ANSWER: (empty)
; AUTHORITY:
example.com.  3600  IN  SOA  ns1.example.com. hostmaster.example.com. 2026093001 7200 900 1209600 300

go deeper

for a junior

Recall the four everyday rcodes: NOERROR for success, NXDOMAIN for a name that does not exist, SERVFAIL for a server that could not answer, and REFUSED for a policy refusal.

for a middle

Explain NODATA as NOERROR with an empty answer and an SOA in the authority section, and contrast it with NXDOMAIN, which denies the name itself and everything below it.

for a senior

Show you can triage from the rcode: NXDOMAIN points at the zone data or the last alias target, SERVFAIL at the servers or validation, REFUSED at who is being asked. Never let SERVFAIL be reported as not found.

for a principal

Argue for error handling that keeps the distinctions: clients and monitoring that collapse NODATA, NXDOMAIN and SERVFAIL into one failure hide outages and misdiagnose zone mistakes.

## Where the rcode lives Every DNS response carries a **response code (rcode)** in the last 4 bits of the header's second 16-bit word, so plain DNS has 16 possible values. RFC 1035 §4.1.1 defines six; the rest were reserved. **EDNS0** (RFC 6891) later extended the rcode to 12 bits by adding an extended part in the `OPT` pseudo-record, which is how codes above 15, such as `BADVERS` (16), exist. | Value | Name | Meaning (RFC 1035) | |---|---|---| | 0 | `NOERROR` | no error condition | | 1 | `FORMERR` | the server could not interpret the query | | 2 | `SERVFAIL` | the server could not process the query because of a problem on its side | | 3 | `NXDOMAIN` | "Name Error": the queried name does not exist | | 4 | `NOTIMP` | the server does not support that kind of query | | 5 | `REFUSED` | the server refuses for policy reasons | RFC 2308 established `NXDOMAIN` as the synonym for Name Error, and RFC 9499 is the current terminology reference for all of these names. ## NXDOMAIN: the name does not exist RFC 1035 says Name Error is meaningful only from an **authoritative server**: it states that the name in the question does not exist in the zone. A recursive resolver that receives it passes it on to its client. Three consequences follow: - **No type exists at that name.** `NXDOMAIN` is about the name, not about the record type asked for. - **Nothing exists below it.** RFC 8020 ("NXDOMAIN: There Really Is Nothing Underneath") says a resolver SHOULD treat every name at or below an `NXDOMAIN` node as nonexistent, so `api.dev.example.com` cannot exist if `dev.example.com` is `NXDOMAIN`. - **With aliases, the missing name is the end of the chain.** If `www.example.com` is a `CNAME` to a target that does not exist, the response carries the `CNAME` in the answer section and the rcode is `NXDOMAIN`; RFC 8020 notes that the nonexistent name is the last one in the chain, not the name you asked for. ## NODATA: the name exists, the type does not **NODATA** has no rcode value. RFC 2308 calls it a **pseudo rcode** that has to be inferred: the rcode is `NOERROR`, the answer section holds no relevant records, and the authority section normally holds the zone's `SOA` record. It means the name is real but has no RRset of the requested type. Classic cases: 1. Asking for `AAAA` at a name that only has an `A` record. 2. Asking for `MX` at a host name that receives no mail. 3. Asking any type at an **empty non-terminal (ENT)**, a name that owns no records but has names below it, such as the `_tcp` label under which `SRV` records live. RFC 8020 calls servers that answer ENTs with `NXDOMAIN` "definitely wrong". A **referral** also has `NOERROR` and an empty answer section; it differs by carrying `NS` records rather than an `SOA` in the authority section, with `AA` clear (RFC 9499). Both negative forms are cached for a time derived from that `SOA`, which is the negative-caching topic. ## SERVFAIL and REFUSED: about the server, not the name `SERVFAIL` says the answering server failed. From a recursive resolver it commonly means every authoritative server for the zone timed out or answered badly, a delegation was broken, or DNSSEC validation failed (RFC 4033 uses `SERVFAIL` to signal bogus data to non-validating stubs). It **proves nothing about existence**: the same name may resolve a minute later or from another resolver. `REFUSED` says the server chose not to answer. Common cases are a recursive resolver that serves only its own clients, a zone-transfer request from an address that is not allowed, and, in common practice, an authoritative-only server asked about a zone it does not serve. ## Reading them in practice | Response | Name exists? | Record type exists? | What to do | |---|---|---|---| | `NOERROR`, answers present | yes | yes | use them | | `NOERROR`, empty answer, `SOA` in authority (NODATA) | yes | no | ask for another type, or fix the zone | | `NXDOMAIN` | no | no | check spelling, delegation, the last alias target | | `SERVFAIL` | unknown | unknown | retry, try another resolver, investigate the zone's servers | | `REFUSED` | unknown | unknown | you are asking the wrong server or are not allowed | ## Common misconceptions - **"NXDOMAIN means no record of that type."** That is NODATA. Confusing the two makes a dual-stack client that gets NODATA for `AAAA` wrongly conclude the host is gone. - **"SERVFAIL means the name is missing."** It means the server could not find out. - **"NODATA is its own rcode."** It is `NOERROR` plus an empty answer; software has to infer it from the sections.

  • A DNS query for www.example.com returns a CNAME in the answer section and rcode NXDOMAIN. Which name does not exist?
    The last name in the alias chain, not `www.example.com`. The alias itself exists, which is why the `CNAME` is in the answer section; its target does not. RFC 8020 warns that the nonexistent name is the last one in the `CNAME` chain rather than the query name, so the fix is to create the target or repoint the alias.
  • Why must an authoritative DNS server answer NODATA, not NXDOMAIN, for a name that has no records but has names below it?
    Such a name is an empty non-terminal: it exists in the tree because its descendants do. `NXDOMAIN` would claim nothing exists at or below it, and under RFC 8020 a resolver may cache that as a cut and deny the descendants too, such as `SRV` records under a `_tcp` label. RFC 8020 calls servers that do this definitely wrong.
  • Is it safe for a client to treat SERVFAIL from a DNS resolver as proof that a name does not exist?
    No. `SERVFAIL` reports that the resolver could not produce an answer, for example because the zone's servers timed out or DNSSEC validation failed. The name may exist and resolve moments later or through another resolver. Treating it as nonexistence turns a transient outage into a hard failure; retry with backoff, try another resolver, and report it as an error distinct from `NXDOMAIN`.

saying these in an interview costs you the question

  • NXDOMAIN means the name has no record of the type I asked for.
  • SERVFAIL proves the queried name does not exist.
  • NODATA is its own response code, separate from NOERROR.
  • A NOERROR response always contains at least one answer record.
  • An NXDOMAIN for a name says nothing about the names beneath it.
  • REFUSED means the queried name is missing from the zone.