WEBINVEST.IT
Glossary

Nameserver

A nameserver is a server that responds to DNS queries for a zone or performs name resolution functions. In the context of a registered domain, authoritative nameservers publish official zone records such as A, AAAA, MX, TXT, and CNAME. The registrar records the delegation with the registry, specifying which nameservers are responsible; users can then locate services associated with the domain. A recursive resolver, on the other hand, seeks answers on behalf of clients and queries the DNS hierarchy when needed. These roles may reside on separate infrastructures and should not be confused.

Delegation and DNS Zone

Domain registration and DNS hosting are distinct services. A domain name can be purchased from one registrar while using nameservers provided by another provider. For a zone change to take effect, the delegation must point to the nameservers that contain it. Modifying records in the wrong panel will have no impact if that panel does not manage the authoritative data. Before migrating, check the current delegation and identify where the authoritative zone resides.

A domain can have multiple authoritative nameservers for redundancy. These servers must serve consistent and reachable data; discrepancies between them may cause intermittent responses. The parent DNS publishes the NS records of the delegation and, in some cases, glue records to reach nameservers hosted under the same domain. When switching providers, new nameservers should be ready with a complete copy of the zone before the delegation is updated. Mail records, verification entries, application services, and DNSSEC records are often overlooked if only the homepage is considered.

Custom Nameservers and Security

A domain owner can use custom nameservers, such as ns1.example.it, or those provided by a hosting provider. In the former case, it may be necessary to register host objects and glue records with the registrar or registry. Addresses must match real servers and remain reachable. An error can halt domain resolution, even if the zone exists. Custom nameservers do not automatically improve performance or security; quality depends on redundancy, patching, monitoring, access control, and zone design.

Accounts managing nameservers are sensitive because changes can redirect websites and email. Strong authentication should be enabled, privileges limited, notifications used, and modifications logged. DNS automation APIs should have minimal permissions and expiration or rotation policies. DNSSEC adds the ability to validate integrity and authenticity of the chain, but misconfigured DS records, keys, or signatures can break resolution. Protection requires procedures and testing—not just enabling an option.

Troubleshooting and Migration

When a site fails to resolve, first verify the public delegation, then query all authoritative nameservers directly to compare responses, serial numbers, and reachability status. Check required records, glue entries, and DNSSEC validation. A recursive resolver may return cached outdated data; querying the authority distinguishes published values from cached ones. A correct response from a nameserver does not guarantee that the web server is configured for the name or that the HTTPS certificate is valid.

In summary, a nameserver refers to servers responsible for DNS information or recursive resolution. For a domain, the delegation determines which provider publishes the actual data. Correctly identifying this layer is essential before modifying records, transferring services, or diagnosing outages.

← Full glossary