WEBINVEST.IT
Glossary

Recursive resolver

A recursive resolver is a DNS server that receives a query from a client and attempts to obtain a complete response by checking its own cache and, if necessary, querying other servers in the DNS hierarchy. The browser or device requests, for example, the IP address associated with a domain name. If the data is not already cached, the resolver may query root servers, TLD nameservers, and authoritative servers for the domain. It then returns the response to the client and may store it according to the TTL value. A recursive resolver acts on behalf of the user, whereas an authoritative server publishes official zone data.

Cache and Path

The cache speeds up resolution and reduces repeated queries to the DNS hierarchy. Each record is stored for its specified TTL, with behaviors and limits defined by the software. Therefore, after a DNS change, the resolver may continue to return the old value until expiration. Resolvers can also cache negative responses for a period. A direct query to an authoritative nameserver shows the published data, while querying a recursive resolver reveals what the client might see at that moment.

The path is not always a long sequence: cached responses avoid further queries. An enterprise resolver may forward queries to another provider, filter domains, enforce security policies, or log metadata. A public service may offer greater availability or features, but the operator sees incoming queries and may have different privacy and retention rules. Choosing a resolver thus involves trust decisions beyond speed considerations.

Recursion, Authority, and Security

A recursive resolver can perform queries for many names, but should not be open to all if it serves a private network. An open resolver can be exploited in amplification attacks and may expose user activity data. Administrators configure access controls, rate limits, and monitoring. Authoritative nameservers can be publicly reachable to serve a zone without accepting recursion for third-party names; separating roles is a recommended practice.

DNSSEC allows resolvers that validate responses to check authenticity and integrity through a chain of signatures. It does not encrypt queries, hide the queried name, or guarantee website security. DNS over HTTPS and DNS over TLS encrypt communication between client and resolver but shift trust to that service. These technologies address different risks and can coexist. If DNSSEC validation detects an inconsistent signature, the resolver may return an error instead of an unverified response.

Troubleshooting and Choice

If a page fails to load, querying multiple resolvers helps determine whether data is cached or delegation is incorrect. One checks the queried server, record type, TTL, and response code, distinguishing between timeouts, NXDOMAIN, and empty responses. A resolver returning a correct IP does not confirm that the web server is active. In enterprise networks, VPNs, or parental controls, local policies may alter responses and affect browsing.

In summary, a recursive resolver resolves names on behalf of the client using cache and the DNS hierarchy. It differs from an authoritative nameserver and plays a key role in performance, privacy, and security. Diagnosis must identify which resolver was queried and how it obtained its response.

← Full glossary