A glue record is a DNS addressing data published in the parent zone to help resolve a nameserver whose name resides within the domain it serves. For example, if example.it delegates its zone to ns1.example.it, the resolver must first know the IP address of ns1.example.it before querying the example.it zone. Without additional data, this would create a circular dependency: resolving the nameserver’s address would require querying that same nameserver. The glue record provides the necessary address at a higher level in the DNS hierarchy.
Dependency and Delegation
Delegation indicates which nameservers are responsible for a zone. The parent, such as a TLD registry, publishes NS records and, when needed, associated glue addresses for hostnames within the delegated domain. Resolvers can then reach the child servers and retrieve the authoritative zone data. A glue record is not the same as an A or AAAA record in the child zone, even though the IP address should align with the authoritative value. The information resides at different levels and serves related but distinct functions.
If nameservers are external to the domain—such as ns.provider.example—the parent typically does not need to provide glue for the client’s domain: the resolver can first resolve the provider's name through its own delegation. Specific requirements depend on the delegation model and domain extension. When registering custom nameservers with a registrar, the domain owner creates or updates host objects and provides addresses according to supported procedures. Simply adding an NS record to the zone is insufficient; the parent must recognize the nameserver required for delegation.
IPv4, IPv6 Consistency and Updates
A nameserver host can have IPv4 glue, IPv6 glue, or both, depending on network configuration and actual support. Publishing an unreachable address may cause timeouts or intermittent responses. Values must match the servers that respond authoritatively and should be updated before or during a coordinated migration. When a nameserver’s IP changes, both the child zone and the parent's glue record must remain consistent to prevent some resolvers from contacting the old endpoint. Delegation caches can prolong the visibility of outdated values.
A glue misconfiguration can make an entire domain or part of its structure unreachable, even if the new server is correctly configured internally. Therefore, verification should include queries to the parent, authoritative servers, and multiple resolvers, distinguishing data sources. Panels may display “host,” “child nameserver,” “registration nameserver,” or “custom nameserver”: it’s essential to confirm that the correct object is being modified. When switching providers, it's advisable to prepare and test the new infrastructure before removing the old server.
Security and Troubleshooting
A glue record alone does not authenticate a nameserver’s identity. DNSSEC can protect the authenticity and integrity of DNS responses along a validated chain but requires correct signatures and delegations. Inconsistent configurations among NS, glue, A/AAAA records, and DS can produce hard-to-interpret errors. When a domain fails to resolve, check delegation and glue at the parent first, then verify reachability, firewalls, and zone data on the servers. Simply testing an IP address does not confirm that the nameserver serves the correct zone.
In summary, a glue record prevents circular dependencies when a nameserver is hosted under the domain it serves. It acts as bootstrap data in the parent DNS and must remain consistent with the authoritative zone and truly reachable addresses.
← Full glossary