DNS
How a name becomes an address: record types, the resolver chain, TTL caching and delegated zones, over plain or encrypted transports. It sits behind every 'what happens when you type a URL' question.
on this pageshowhide
explore
- Record Types6 questions
- Resolution Flow6 questions
- Header, Rcodes and Transport4 questions
- Caching and TTL5 questions
- Zones and Delegation6 questions
- Answer Steering and Failover5 questions
- Resolver Privacy and Attacks5 questions
questions
page 2 of 2What is split-horizon DNS, and what problems appear when authoritative servers give internal and external clients different views of the same names?
basics
~20 sSplit-horizon DNS has authoritative servers answer the same names differently depending on who asks, usually an internal and an external view. Costs: two versions to keep consistent, answers that depend on the resolver's location, leaks between views, and confusing debugging.
How do you choose DNS TTLs for a service that relies on DNS-based failover, and what do very short TTLs cost you?
basics
~20 sWorst-case DNS failover time is detection plus publishing plus one full TTL, so failover names need short TTLs. Short TTLs cost query load, lookup latency and dependence on authoritative uptime, so set them per record, not zone-wide.
How would you choose a DNS answer-steering design for a service in three regions when its failover speed is bounded by recursive resolver caches you do not control?
basics
~20 sTreat DNS steering as locality and minutes-scale evacuation, not seconds-scale failover: anycast the name servers, key answers on ECS where sent, return a local plus an alternate address, fail open, and put faster failover below DNS.
Your zone's authoritative DNS servers are unreachable for two hours; what does serve-stale (RFC 8767) let a recursive resolver do, and within what limits?
basics
~20 sServe-stale (RFC 8767) lets a recursive resolver answer with records whose TTL has expired when it cannot refresh them from the authoritative servers, returning them with a short TTL (30 seconds recommended) and keeping them only for a bounded time.
What does a DNS CAA record at example.com actually enforce when a certificate authority is asked to issue for shop.example.com, and what does it not protect against?
basics
~20 sA compliant CA must look up CAA before issuing, climbing from shop.example.com toward the root to the first CAA set, and refuse if that set excludes it. Browsers must not check CAA, so rogue CAs are not stopped.
Without QNAME minimisation, what does a recursive DNS resolver reveal to root and TLD servers, and how does RFC 9156 change what each server sees?
basics
~20 sTraditionally every server on the path receives the full name and query type. Under RFC 9156 the resolver sends each server only one label more than the zone it serves, with a neutral type such as A.
Lookups under a delegated DNS subdomain are intermittently slow, and one of its listed name servers answers REFUSED for the zone; what is a lame delegation, and why does it hurt?
basics
~20 sA lame delegation is an NS record naming a server that does not serve the zone. Resolvers that pick it lose a round trip or a timeout before retrying elsewhere, and lookups fail if every listed server is lame.
showing 31–37 of 37