WEBINVEST.IT
Glossary

Authoritative DNS

An authoritative DNS server is one that provides definitive answers for a DNS zone it manages. When a client queries a record for a domain, a resolver can traverse the hierarchical DNS infrastructure to reach the authoritative nameservers delegated for that zone. These servers publish records configured by the domain owner or their provider: IP addresses, mail servers, aliases, delegations, and other data. “Authoritative” refers to the server’s role within the zone, not a general level of trust across the entire Internet. The server responds based on its zone data and configuration, without performing the same recursive lookup that user-facing resolvers do.

A domain can be served by multiple authoritative nameservers for redundancy and availability. The parent DNS, such as the TLD registry, publishes the delegation indicating which nameservers are responsible. For the root zone or a TLD, authoritative servers publish data relevant to their level; for a registered domain, the servers listed in the delegation publish the corresponding zone. In some cases, the server holds the data directly; in others, it forwards queries to an authoritative backend. Internal architecture varies, but clients must receive consistent responses and reach nameservers via IPv4 and, where applicable, IPv6.

Authoritative vs Recursive

A recursive resolver acts on behalf of the client: it receives a query and, if not cached, contacts other servers until it finds the data or an error. An authoritative server responds only for the zone it manages and typically does not seek answers outside that zone on behalf of the requester. A resolver may cache a response for its TTL and serve it to multiple users; an authoritative server is instead the source from which responses are retrieved or updated. Confusing these roles can lead to misconfigurations, such as exposing an open resolver or expecting every nameserver to return recursive records for any domain.

The distinction between authoritative and cached responses is critical during DNS changes. A direct query to an authoritative nameserver shows the data currently published by that server; a query to a public resolver may show a cached response until its TTL expires. If authoritative nameservers are not synchronized, different queries may return inconsistent results. After a zone change, checking all nameservers listed in the delegation and querying multiple resolvers helps distinguish between cache delays and incomplete or incorrect delegations.

Zone Management

The DNS zone is the administrated container managed by authoritative nameservers. The registrar can also be the DNS provider, but often these are separate services. Changing registrars does not necessarily change nameservers; changing nameservers requires that the new zone is ready and includes all necessary records. An incomplete zone can disrupt websites, email, subdomains, and verification checks. It is good practice to export configurations, document dependencies, maintain reasonable TTLs before migration, and plan rollbacks. Zone management should include limited roles, strong authentication, and change tracking.

Authoritative nameservers may be anycast or distributed across multiple data centers, but this does not alter their logical role. Anycast concerns network routing to instances; authority concerns zone data responsibility. DNSSEC can sign published responses, adding cryptographic validation of the trust chain if the zone and delegation are correctly configured. Neither of these properties guarantees that website content is legitimate or up-to-date. In short, an authoritative DNS server is the source of records for a zone, distinct from resolvers that query and cache responses for users.

← Full glossary