{
    "version": "https://jsonfeed.org/version/1",
    "title": "Maytham Alsudany's blog",
    "home_page_url": "https://maytham.aezign.au/blog",
    "feed_url": "https://maytham.aezign.au/feeds/index.json",
    "description": "Read about Maytham's software and system administration insights, research and more.",
    "author": {
        "name": "Maytham Alsudany",
        "url": "https://maytham.aezign.au"
    },
    "items": [
        {
            "id": "https://aezign.com.au/resources/how-dns-and-nameservers-work",
            "content_html": "<!--[--><article><p>The Domain Name System (DNS) is a fundamental piece of technology behind the modern internet. Thanks to its introduction in 1983, you're able to enter domain names like <code>aezign.com.au</code> instead of raw IP addresses in your browser's address bar and when sending emails. This article explains what it is, how it works, and how you can inspect your own website's DNS and ensure it is set up correctly.</p><h2 id=\"dns-in-a-nutshell\">DNS in a nutshell</h2><p>A well-used analogy is a phonebook; when you have someone's name and need to find their phone number, you look through the phonebook. Overall, DNS does the same thing: when you enter an address like example.com, your browser will contact a DNS server (the \"phonebook\") to determine its IP addresses. On Linux (or MacOS) systems, you can use <a href=\"https://manpages.debian.org/stable/bind9-dnsutils/dig.1.en.html\"><code>dig</code></a> on the command line to perform a DNS lookup and see what this looks like:</p><!--[-1--><pre>$ dig example.com\n\n; &lt;&lt;>> DiG 9.20.29-1-Debian &lt;&lt;>> example.com\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 42782\n;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1\n\n;; OPT PSEUDOSECTION:\n; EDNS: version: 0, flags:; udp: 1232\n;; QUESTION SECTION:\n;example.com.                   IN      A\n\n;; ANSWER SECTION:\nexample.com.            221     IN      A       104.20.23.154\nexample.com.            221     IN      A       172.66.147.243\n\n;; Query time: 20 msec\n;; SERVER: 1.1.1.1#53(1.1.1.1) (UDP)\n;; WHEN: Sun Sep 27 21:07:50 AWST 2026\n;; MSG SIZE  rcvd: 72</pre><!--]--><!----><p>Here, you can see the DNS server being used is <code>1.1.1.1</code> (Cloudflare's DNS server), and that it found the IPs <code>104.20.23.154</code> and <code>172.66.147.243</code> associated with the domain name <code>example.com</code>. Your browser will then contact these IP addresses directly to load the website you are trying to open.</p><h3 id=\"configuring-dns-servers\">Configuring DNS servers</h3><p>You can configure DNS servers through your operating system's network settings, and for some applications such as Firefox, with the application itself. If you don't manually set a DNS server, your computer will use the ones provided by your modem. If those are not configured, the default defined by the modem manufacturer or your ISP will be used.</p><p>The most well-used and reliable DNS servers you can use are Cloudflare's (<code>1.1.1.1</code> and <code>1.0.0.1</code>) and Google's (<code>8.8.8.8</code> and <code>8.8.4.4</code>). Having more than one DNS server means that if the first one in the list doesn't work or doesn't find the matching IPs for a domain name, it will move to the next one in the list, a backup DNS server.</p><p>DNS servers must be configured as IP addresses. If your computer tried to use a DNS server at a domain name, then where would your computer find the IP address for that domain name? It wouldn't be able to, as this is the exact gap that DNS servers fulfill.</p><h2 id=\"records\">Records</h2><p>DNS is not used only to find IPs for a domain, but a whole host of other things. Collectively they are referred to as \"records\" (or \"DNS records\"). Each record is associated to a domain (e.g. <code>example.com</code>) or a subdomain (e.g. <code>bar.example.com</code>, <code>foo.bar.example.com</code>) Here are some of the most common and important types:</p><ul><li><p>A - Map to an IPv4 address (e.g. <code>104.20.23.154</code>).</p><p>This is the fundamental function of DNS: to map from a domain name to a server's IP address. Multiple A records leads to load balancing, where browsers will randomly select one of the returned IP addresses such that traffic is evenly split between them.</p></li><li><p>AAAA - Map to an IPv6 address (e.g. <code>2606:4700:10::6814:179a</code>).</p><p>This serves the same purpose as A records but for IPv6. Multiple AAAA records results in the same load balancing behaviour. All modern websites should have both an A record for legacy compatibility, and an AAAA record to future-proof for the gradual shift towards IPv6 addresses.</p></li><li><p>CNAME - Alias to another domain name (e.g. <code>example.com</code>).</p><p>DNS servers will recursively lookup records for the aliased domain name until they reach an IP address (in an A or AAAA record).</p></li><li><p>MX - Specify a Mail Exchange server (e.g. <code>mail.example.com</code>).</p><p>This record tells email SMTP servers where to direct emails to. For instance, the MX record for <code>aezign.com.au</code> is <code>mail.aezign.au</code>; this directs SMTP servers like Gmail and Outlook to send emails to the mailserver running at <code>mail.aezign.au</code>. This also allows specifying a priority field, so that you can define multiple MX records (such as a main and a backup) and consumers will try to connect to the listed mailservers from lowest priority to highest.</p></li><li><p>TXT - Store arbitrary text data</p><p>This is most commonly used for site verification (for instance, to link your website to Google Search Console) and for email security measures like DKIM, DMARC, and SPF.</p></li><li><p>NS - Specify the nameservers for a domain (e.g. <code>zeus.ns.cloudflare.com</code>).</p><p>These authoritative nameservers are responsible for providing all the other record types when needed.</p></li></ul><p><code>dig</code> lets you query each of these. For instance, to list the MX records against <code>aezign.com.au</code>:</p><!--[-1--><pre>$ dig MX aezign.com.au\n\n; &lt;&lt;>> DiG 9.20.29-1-Debian &lt;&lt;>> MX aezign.com.au\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 28213\n;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1\n\n;; OPT PSEUDOSECTION:\n; EDNS: version: 0, flags:; udp: 1232\n;; QUESTION SECTION:\n;aezign.com.au.                 IN      MX\n\n;; ANSWER SECTION:\naezign.com.au.          300     IN      MX      10 mail.aezign.au.\n\n;; Query time: 104 msec\n;; SERVER: 1.1.1.1#53(1.1.1.1) (UDP)\n;; WHEN: Sun Sep 27 22:04:58 AWST 2026\n;; MSG SIZE  rcvd: 70</pre><!--]--><!----><p>Here you can see there is only one mailserver configured for <code>aezign.com.au</code>, which is <code>mail.aezign.au</code>, and it has a priority of 10.</p><p>If you compare this against something like <code>gmail.com</code>:</p><!--[-1--><pre>$ dig MX gmail.com\n\n; &lt;&lt;>> DiG 9.20.29-1-Debian &lt;&lt;>> MX gmail.com\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 16538\n;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1\n\n;; OPT PSEUDOSECTION:\n; EDNS: version: 0, flags:; udp: 1232\n;; QUESTION SECTION:\n;gmail.com.                     IN      MX\n\n;; ANSWER SECTION:\ngmail.com.              2497    IN      MX      40 alt4.gmail-smtp-in.l.google.com.\ngmail.com.              2497    IN      MX      20 alt2.gmail-smtp-in.l.google.com.\ngmail.com.              2497    IN      MX      5 gmail-smtp-in.l.google.com.\ngmail.com.              2497    IN      MX      10 alt1.gmail-smtp-in.l.google.com.\ngmail.com.              2497    IN      MX      30 alt3.gmail-smtp-in.l.google.com.\n\n;; Query time: 120 msec\n;; SERVER: 1.1.1.1#53(1.1.1.1) (UDP)\n;; WHEN: Sun Sep 27 22:06:04 AWST 2026\n;; MSG SIZE  rcvd: 161</pre><!--]--><!----><p>You can see that <code>gmail.com</code> has several mailservers configured as redundancies due to the Gmail's sheer scale. <code>gmail-smtp-in.l.google.com</code> has the highest priority of 5, so SMTP servers will attempt to contact that mailserver first, followed by <code>alt1.gmail-smtp-in.l.google.com</code> and so on.</p><h2 id=\"nameservers\">Nameservers</h2><p>Now there needs to be somewhere for DNS records against a domain name to be defined, right? This is where nameservers come in.</p><p>Nameservers are DNS servers that answer queries about the domains they are authoritative for i.e. the domains they are in charge of. For example, the authoritative nameservers for <code>example.com</code> are <code>hera.ns.cloudflare.com</code> and <code>elliott.ns.cloudflare.com</code>, which means Cloudflare's nameservers are the source of truth when looking up DNS records for <code>example.com</code>. You can check this with <code>dig</code>:</p><!--[-1--><pre>$ dig NS example.com\n\n; &lt;&lt;>> DiG 9.20.29-1-Debian &lt;&lt;>> NS example.com\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 37717\n;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1\n\n;; OPT PSEUDOSECTION:\n; EDNS: version: 0, flags:; udp: 1232\n;; QUESTION SECTION:\n;example.com.                   IN      NS\n\n;; ANSWER SECTION:\nexample.com.            81837   IN      NS      hera.ns.cloudflare.com.\nexample.com.            81837   IN      NS      elliott.ns.cloudflare.com.\n\n;; Query time: 140 msec\n;; SERVER: 1.1.1.1#53(1.1.1.1) (UDP)\n;; WHEN: Sun Sep 27 23:27:19 AWST 2026\n;; MSG SIZE  rcvd: 95</pre><!--]--><!----><p>Nameservers are configured with your domain name's registrar. The nameserver you set dictates where your remaining DNS records will live. For <code>example.com</code>, this means you would configure all your records on Cloudflare's dashboard, since they are responsible for the domain's DNS records.</p><h2 id=\"recursive-resolution\">Recursive resolution</h2><p>The DNS servers that our computers use follow a <strong>recursive resolution</strong> process behind-the-scenes to find the authoritative nameservers for a domain, followed by the records you are querying.</p><h3 id=\"finding-the-root-nameservers\">Finding the root nameservers</h3><p>Due to the recursive nature of the resolution process, there needs to be a starting point: the root (<code>.</code>) nameservers. The resolver uses a fixed list of root nameservers called <a href=\"https://www.iana.org/domains/root/files\">root hints</a> issued by IANA (<a href=\"https://www.internic.net/domain/named.root\"><code>named.root</code></a>), to locate and contact the root nameservers. Resolvers will have this provided to them initially, and can dynamically update it themselves by querying one of the root nameservers for the root NS records to obtain a fresh list. For instance, we can query <code>198.41.0.4</code> (<code>a.root-servers.net</code>) to obtain a new list of root nameservers:</p><!--[-1--><pre>$ dig @198.41.0.4 NS .\n\n; &lt;&lt;>> DiG 9.20.29-1-Debian &lt;&lt;>> @198.41.0.4 NS .\n; (1 server found)\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 43677\n;; flags: qr aa rd; QUERY: 1, ANSWER: 13, AUTHORITY: 0, ADDITIONAL: 27\n;; WARNING: recursion requested but not available\n\n;; OPT PSEUDOSECTION:\n; EDNS: version: 0, flags:; udp: 4096\n;; QUESTION SECTION:\n;.\t\t\t\tIN\tNS\n\n;; ANSWER SECTION:\n.\t\t\t518400\tIN\tNS\tl.root-servers.net.\n.\t\t\t518400\tIN\tNS\tj.root-servers.net.\n.\t\t\t518400\tIN\tNS\tf.root-servers.net.\n.\t\t\t518400\tIN\tNS\th.root-servers.net.\n.\t\t\t518400\tIN\tNS\td.root-servers.net.\n.\t\t\t518400\tIN\tNS\tb.root-servers.net.\n.\t\t\t518400\tIN\tNS\tk.root-servers.net.\n.\t\t\t518400\tIN\tNS\ti.root-servers.net.\n.\t\t\t518400\tIN\tNS\tm.root-servers.net.\n.\t\t\t518400\tIN\tNS\te.root-servers.net.\n.\t\t\t518400\tIN\tNS\tg.root-servers.net.\n.\t\t\t518400\tIN\tNS\tc.root-servers.net.\n.\t\t\t518400\tIN\tNS\ta.root-servers.net.\n\n;; ADDITIONAL SECTION:\nl.root-servers.net.\t518400\tIN\tA\t199.7.83.42\nl.root-servers.net.\t518400\tIN\tAAAA\t2001:500:9f::42\nj.root-servers.net.\t518400\tIN\tA\t192.58.128.30\nj.root-servers.net.\t518400\tIN\tAAAA\t2001:503:c27::2:30\nf.root-servers.net.\t518400\tIN\tA\t192.5.5.241\nf.root-servers.net.\t518400\tIN\tAAAA\t2001:500:2f::f\nh.root-servers.net.\t518400\tIN\tA\t198.97.190.53\nh.root-servers.net.\t518400\tIN\tAAAA\t2001:500:1::53\nd.root-servers.net.\t518400\tIN\tA\t199.7.91.13\nd.root-servers.net.\t518400\tIN\tAAAA\t2001:500:2d::d\nb.root-servers.net.\t518400\tIN\tA\t170.247.170.2\nb.root-servers.net.\t518400\tIN\tAAAA\t2801:1b8:10::b\nk.root-servers.net.\t518400\tIN\tA\t193.0.14.129\nk.root-servers.net.\t518400\tIN\tAAAA\t2001:7fd::1\ni.root-servers.net.\t518400\tIN\tA\t192.36.148.17\ni.root-servers.net.\t518400\tIN\tAAAA\t2001:7fe::53\nm.root-servers.net.\t518400\tIN\tA\t202.12.27.33\nm.root-servers.net.\t518400\tIN\tAAAA\t2001:dc3::35\ne.root-servers.net.\t518400\tIN\tA\t192.203.230.10\ne.root-servers.net.\t518400\tIN\tAAAA\t2001:500:a8::e\ng.root-servers.net.\t518400\tIN\tA\t192.112.36.4\ng.root-servers.net.\t518400\tIN\tAAAA\t2001:500:12::d0d\nc.root-servers.net.\t518400\tIN\tA\t192.33.4.12\nc.root-servers.net.\t518400\tIN\tAAAA\t2001:500:2::c\na.root-servers.net.\t518400\tIN\tA\t198.41.0.4\na.root-servers.net.\t518400\tIN\tAAAA\t2001:503:ba3e::2:30\n\n;; Query time: 476 msec\n;; SERVER: 198.41.0.4#53(198.41.0.4) (UDP)\n;; WHEN: Mon Sep 28 00:01:08 AWST 2026\n;; MSG SIZE  rcvd: 811</pre><!--]--><!----><h3 id=\"querying-the-root-nameservers\">Querying the root nameservers</h3><p>For <code>example.com</code>, the first step is to query the root (<code>.</code>) nameservers to find the nameservers for the <code>.com</code> top-level domain (TLD). Using <code>a.root-servers.net</code> again:</p><!--[-1--><pre>$ dig @198.41.0.4 NS com\n\n; &lt;&lt;>> DiG 9.20.29-1-Debian &lt;&lt;>> @198.41.0.4 NS com\n; (1 server found)\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 22528\n;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 13, ADDITIONAL: 27\n;; WARNING: recursion requested but not available\n\n;; OPT PSEUDOSECTION:\n; EDNS: version: 0, flags:; udp: 4096\n;; QUESTION SECTION:\n;com.\t\t\t\tIN\tNS\n\n;; AUTHORITY SECTION:\ncom.\t\t\t172800\tIN\tNS\tl.gtld-servers.net.\ncom.\t\t\t172800\tIN\tNS\tj.gtld-servers.net.\ncom.\t\t\t172800\tIN\tNS\th.gtld-servers.net.\ncom.\t\t\t172800\tIN\tNS\td.gtld-servers.net.\ncom.\t\t\t172800\tIN\tNS\tb.gtld-servers.net.\ncom.\t\t\t172800\tIN\tNS\tf.gtld-servers.net.\ncom.\t\t\t172800\tIN\tNS\tk.gtld-servers.net.\ncom.\t\t\t172800\tIN\tNS\tm.gtld-servers.net.\ncom.\t\t\t172800\tIN\tNS\ti.gtld-servers.net.\ncom.\t\t\t172800\tIN\tNS\tg.gtld-servers.net.\ncom.\t\t\t172800\tIN\tNS\ta.gtld-servers.net.\ncom.\t\t\t172800\tIN\tNS\tc.gtld-servers.net.\ncom.\t\t\t172800\tIN\tNS\te.gtld-servers.net.\n\n;; ADDITIONAL SECTION:\nl.gtld-servers.net.\t172800\tIN\tA\t192.41.162.30\nl.gtld-servers.net.\t172800\tIN\tAAAA\t2001:500:d937::30\nj.gtld-servers.net.\t172800\tIN\tA\t192.48.79.30\nj.gtld-servers.net.\t172800\tIN\tAAAA\t2001:502:7094::30\nh.gtld-servers.net.\t172800\tIN\tA\t192.54.112.30\nh.gtld-servers.net.\t172800\tIN\tAAAA\t2001:502:8cc::30\nd.gtld-servers.net.\t172800\tIN\tA\t192.31.80.30\nd.gtld-servers.net.\t172800\tIN\tAAAA\t2001:500:856e::30\nb.gtld-servers.net.\t172800\tIN\tA\t192.33.14.30\nb.gtld-servers.net.\t172800\tIN\tAAAA\t2001:503:231d::2:30\nf.gtld-servers.net.\t172800\tIN\tA\t192.35.51.30\nf.gtld-servers.net.\t172800\tIN\tAAAA\t2001:503:d414::30\nk.gtld-servers.net.\t172800\tIN\tA\t192.52.178.30\nk.gtld-servers.net.\t172800\tIN\tAAAA\t2001:503:d2d::30\nm.gtld-servers.net.\t172800\tIN\tA\t192.55.83.30\nm.gtld-servers.net.\t172800\tIN\tAAAA\t2001:501:b1f9::30\ni.gtld-servers.net.\t172800\tIN\tA\t192.43.172.30\ni.gtld-servers.net.\t172800\tIN\tAAAA\t2001:503:39c1::30\ng.gtld-servers.net.\t172800\tIN\tA\t192.42.93.30\ng.gtld-servers.net.\t172800\tIN\tAAAA\t2001:503:eea3::30\na.gtld-servers.net.\t172800\tIN\tA\t192.5.6.30\na.gtld-servers.net.\t172800\tIN\tAAAA\t2001:503:a83e::2:30\nc.gtld-servers.net.\t172800\tIN\tA\t192.26.92.30\nc.gtld-servers.net.\t172800\tIN\tAAAA\t2001:503:83eb::30\ne.gtld-servers.net.\t172800\tIN\tA\t192.12.94.30\ne.gtld-servers.net.\t172800\tIN\tAAAA\t2001:502:1ca1::30\n\n;; Query time: 772 msec\n;; SERVER: 198.41.0.4#53(198.41.0.4) (UDP)\n;; WHEN: Mon Sep 28 00:09:25 AWST 2026\n;; MSG SIZE  rcvd: 828</pre><!--]--><!----><h3 id=\"querying-the-tld-nameservers\">Querying the TLD nameservers</h3><p>Now the resolver has <code>.com</code> nameservers and their IPs. We can use one of these, such as <code>192.5.6.30</code> (<code>a.gtld-servers.net</code>) to find the nameservers for <code>example.com</code>:</p><!--[-1--><pre>$ dig @192.5.6.30 NS example.com\n\n; &lt;&lt;>> DiG 9.20.29-1-Debian &lt;&lt;>> @192.5.6.30 NS example.com\n; (1 server found)\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 37419\n;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 2, ADDITIONAL: 13\n;; WARNING: recursion requested but not available\n\n;; OPT PSEUDOSECTION:\n; EDNS: version: 0, flags:; udp: 4096\n;; QUESTION SECTION:\n;example.com.                   IN      NS\n\n;; AUTHORITY SECTION:\nexample.com.            172800  IN      NS      hera.ns.cloudflare.com.\nexample.com.            172800  IN      NS      elliott.ns.cloudflare.com.\n\n;; ADDITIONAL SECTION:\nhera.ns.cloudflare.com. 172800  IN      A       108.162.192.162\nhera.ns.cloudflare.com. 172800  IN      A       172.64.32.162\nhera.ns.cloudflare.com. 172800  IN      A       173.245.58.162\nhera.ns.cloudflare.com. 172800  IN      AAAA    2606:4700:50::adf5:3aa2\nhera.ns.cloudflare.com. 172800  IN      AAAA    2803:f800:50::6ca2:c0a2\nhera.ns.cloudflare.com. 172800  IN      AAAA    2a06:98c1:50::ac40:20a2\nelliott.ns.cloudflare.com. 172800 IN    A       108.162.195.228\nelliott.ns.cloudflare.com. 172800 IN    A       162.159.44.228\nelliott.ns.cloudflare.com. 172800 IN    A       172.64.35.228\nelliott.ns.cloudflare.com. 172800 IN    AAAA    2606:4700:58::a29f:2ce4\nelliott.ns.cloudflare.com. 172800 IN    AAAA    2803:f800:50::6ca2:c3e4\nelliott.ns.cloudflare.com. 172800 IN    AAAA    2a06:98c1:50::ac40:23e4\n\n;; Query time: 80 msec\n;; SERVER: 192.5.6.30#53(192.5.6.30) (UDP)\n;; WHEN: Mon Sep 28 00:12:19 AWST 2026\n;; MSG SIZE  rcvd: 359</pre><!--]--><!----><h3 id=\"finding-the-domains-nameserver\">Finding the domain's nameserver</h3><p>The response tells the resolver that the nameservers for <code>example.com</code> are <code>hera.ns.cloudflare.com</code> and <code>elliott.ns.cloudflare.com</code>. Now since these Cloudflare nameservers are also <code>.com</code> domains and Cloudflare is so commonly used, the <code>.com</code> nameserver provides optional <strong>sibling glue</strong> records as defined in <a href=\"https://datatracker.ietf.org/doc/html/rfc9471\">RFC 9471</a> to prevent further roundtrips and optimize the process.</p><p>If we ignore the sibling glue records provided, the resolver would have to ask the <code>.com</code> nameservers for the nameservers for <code>cloudflare.com</code>:</p><!--[-1--><pre>$ dig @192.5.6.30 NS cloudflare.com\n\n; &lt;&lt;>> DiG 9.20.29-1-Debian &lt;&lt;>> @192.5.6.30 NS cloudflare.com\n; (1 server found)\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 40307\n;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 5, ADDITIONAL: 21\n;; WARNING: recursion requested but not available\n\n;; OPT PSEUDOSECTION:\n; EDNS: version: 0, flags:; udp: 4096\n;; QUESTION SECTION:\n;cloudflare.com.                        IN      NS\n\n;; AUTHORITY SECTION:\ncloudflare.com.         172800  IN      NS      ns3.cloudflare.com.\ncloudflare.com.         172800  IN      NS      ns5.cloudflare.com.\ncloudflare.com.         172800  IN      NS      ns4.cloudflare.com.\ncloudflare.com.         172800  IN      NS      ns6.cloudflare.com.\ncloudflare.com.         172800  IN      NS      ns7.cloudflare.com.\n\n;; ADDITIONAL SECTION:\nns3.cloudflare.com.     172800  IN      A       162.159.0.33\nns3.cloudflare.com.     172800  IN      A       162.159.7.226\nns3.cloudflare.com.     172800  IN      AAAA    2400:cb00:2049:1::a29f:21\nns3.cloudflare.com.     172800  IN      AAAA    2400:cb00:2049:1::a29f:7e2\nns5.cloudflare.com.     172800  IN      A       162.159.2.9\nns5.cloudflare.com.     172800  IN      A       162.159.9.55\nns5.cloudflare.com.     172800  IN      AAAA    2400:cb00:2049:1::a29f:209\nns5.cloudflare.com.     172800  IN      AAAA    2400:cb00:2049:1::a29f:937\nns4.cloudflare.com.     172800  IN      A       162.159.1.33\nns4.cloudflare.com.     172800  IN      A       162.159.8.55\nns4.cloudflare.com.     172800  IN      AAAA    2400:cb00:2049:1::a29f:121\nns4.cloudflare.com.     172800  IN      AAAA    2400:cb00:2049:1::a29f:837\nns6.cloudflare.com.     172800  IN      A       162.159.3.11\nns6.cloudflare.com.     172800  IN      A       162.159.5.6\nns6.cloudflare.com.     172800  IN      AAAA    2400:cb00:2049:1::a29f:30b\nns6.cloudflare.com.     172800  IN      AAAA    2400:cb00:2049:1::a29f:506\nns7.cloudflare.com.     172800  IN      A       162.159.4.8\nns7.cloudflare.com.     172800  IN      A       162.159.6.6\nns7.cloudflare.com.     172800  IN      AAAA    2400:cb00:2049:1::a29f:408\nns7.cloudflare.com.     172800  IN      AAAA    2400:cb00:2049:1::a29f:606\n\n;; Query time: 163 msec\n;; SERVER: 192.5.6.30#53(192.5.6.30) (UDP)\n;; WHEN: Mon Sep 28 00:26:53 AWST 2026\n;; MSG SIZE  rcvd: 573</pre><!--]--><!----><p>Here, the <code>.com</code> nameserver provides <strong>in-domain glue</strong> records for <code>cloudflare.com</code>'s nameservers. Without these, there would be a circular dependency, since the nameserver named is a subdomain of the domain being queried for. This is because nameservers are always defined by name, which means that in order to actually contact the nameserver, your computer needs to obtain its IP address with another DNS lookup.</p><p>Next, we'd use one of these nameservers, say <code>ns3.cloudflare.com</code>, to obtain the IP for <code>hera.ns.cloudflare.com</code>:</p><!--[-1--><pre>$ dig @162.159.0.33 hera.ns.cloudflare.com\n\n; &lt;&lt;>> DiG 9.20.29-1-Debian &lt;&lt;>> @162.159.0.33 hera.ns.cloudflare.com\n; (1 server found)\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 16801\n;; flags: qr aa rd; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1\n;; WARNING: recursion requested but not available\n\n;; OPT PSEUDOSECTION:\n; EDNS: version: 0, flags:; udp: 1232\n;; QUESTION SECTION:\n;hera.ns.cloudflare.com.                IN      A\n\n;; ANSWER SECTION:\nhera.ns.cloudflare.com. 86353   IN      A       108.162.192.162\nhera.ns.cloudflare.com. 86353   IN      A       173.245.58.162\nhera.ns.cloudflare.com. 86353   IN      A       172.64.32.162\n\n;; Query time: 123 msec\n;; SERVER: 162.159.0.33#53(162.159.0.33) (UDP)\n;; WHEN: Mon Sep 28 01:11:37 AWST 2026\n;; MSG SIZE  rcvd: 99</pre><!--]--><!----><h3 id=\"querying-the-domains-authoritative-nameserver\">Querying the domain's authoritative nameserver</h3><p>Now we've reached the authoritative nameserver for <code>example.com</code>! The last thing to do is to fetch the A record for <code>example.com</code> to obtain its server's IP address:</p><!--[-1--><pre>$ dig @108.162.192.162 example.com\n\n; &lt;&lt;>> DiG 9.20.29-1-Debian &lt;&lt;>> @108.162.192.162 example.com\n; (1 server found)\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 43082\n;; flags: qr aa rd; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1\n;; WARNING: recursion requested but not available\n\n;; OPT PSEUDOSECTION:\n; EDNS: version: 0, flags:; udp: 1232\n;; QUESTION SECTION:\n;example.com.                   IN      A\n\n;; ANSWER SECTION:\nexample.com.            300     IN      A       104.20.23.154\nexample.com.            300     IN      A       172.66.147.243\n\n;; Query time: 123 msec\n;; SERVER: 108.162.192.162#53(108.162.192.162) (UDP)\n;; WHEN: Mon Sep 28 01:13:47 AWST 2026\n;; MSG SIZE  rcvd: 72</pre><!--]--><!----><p>At last, we've determined that the IP addresses of the servers behind <code>example.com</code> are <code>104.20.23.154</code> and <code>172.66.147.243</code>. This matches our earlier lookup directly against your computer's configured DNS server.</p><p>The DNS servers your computer uses employ this recursive resolution technique behind the scenes, so that your computer only needs to make one round trip, and the servers can use their much faster data center connections and caching to optimize the process and make the query as fast as possible.</p><h2 id=\"verify-your-dns-records\">Verify your DNS records</h2><p>To check your website's records, the first thing you'll want to do is ensure your domain name is pointed at the correct nameserver. For instance, <code>aezign.com.au</code> is supposed to use Cloudflare, since that is where all the DNS records have been set up. We can verify this using <code>dig</code>, (or alternatively with online tools like <a href=\"https://dnschecker.org\">dnschecker.org</a>):</p><!--[-1--><pre>$ dig NS aezign.com.au\n\n; &lt;&lt;>> DiG 9.20.29-1-Debian &lt;&lt;>> NS aezign.com.au\n;; global options: +cmd\n;; Got answer:\n;; ->>HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 44172\n;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1\n\n;; OPT PSEUDOSECTION:\n; EDNS: version: 0, flags:; udp: 1232\n;; QUESTION SECTION:\n;aezign.com.au.                 IN      NS\n\n;; ANSWER SECTION:\naezign.com.au.          86400   IN      NS      rosalie.ns.cloudflare.com.\naezign.com.au.          86400   IN      NS      zeus.ns.cloudflare.com.\n\n;; Query time: 92 msec\n;; SERVER: 1.1.1.1#53(1.1.1.1) (UDP)\n;; WHEN: Mon Sep 28 01:39:22 AWST 2026\n;; MSG SIZE  rcvd: 100</pre><!--]--><!----><p>If this is not set correctly, the DNS records you configure will not work, as resolvers will be fetching records from somewhere else. In most cases, you can update this in your domain registrar's settings. This is especially common for new domain names, which default to the registrar's nameservers; unless you plan to use their built-in DNS management, you'll need to point them to your chosen provider.</p><p>Now we can check that the DNS records you've configured match those your DNS server returns. For <code>aezign.com.au</code>, these are the MX and TXT records configured on Cloudflare.</p><figure class=\"mx-auto w-fit\"><!--[0--><!--[-1--><picture><!--[--><source srcset=\"/_app/immutable/assets/aezign.com.au-cloudflare-dns-records.zdvJdZD3.avif 1x, /_app/immutable/assets/aezign.com.au-cloudflare-dns-records.D75BSdVY.avif 1.9979879275653925x\" type=\"image/avif\"/><source srcset=\"/_app/immutable/assets/aezign.com.au-cloudflare-dns-records.BAsS_O9w.webp 1x, /_app/immutable/assets/aezign.com.au-cloudflare-dns-records.jHjZCFLp.webp 1.9979879275653925x\" type=\"image/webp\"/><source srcset=\"/_app/immutable/assets/aezign.com.au-cloudflare-dns-records.DINuvsf-.png 1x, /_app/immutable/assets/aezign.com.au-cloudflare-dns-records.DzdwFvIV.png 1.9979879275653925x\" type=\"image/png\"/><!--]--> <img src=\"/_app/immutable/assets/aezign.com.au-cloudflare-dns-records.DzdwFvIV.png\" alt=\"Extract of Cloudflare's DNS record listing showing the MX record and TXT records for aezign.com.au.\" class=\"mx-0\" width=\"993\" height=\"200\" onload=\"this.__e=event\" onerror=\"this.__e=event\"/></picture><!--]--><!--]--><!----> <!--[0--><figcaption><p>The MX record and some TXT records configured for <code>aezign.com.au</code> on Cloudflare's dashboard.</p><!----></figcaption><!--]--></figure><!----><p>We can check these using <code>dig</code>, and using the <code>+short</code> option to show only the content of the records.</p><!--[-1--><pre>$ dig MX aezign.com.au +short\n\n10 mail.aezign.au.\n\n$ dig TXT aezign.com.au +short\n\n\"google-site-verification=KFqTU5xH8fFf6OtszEL4oudfxple29Tm-TvxVtCWkAM\"\n\"v=spf1 mx a:mail.aezign.au -all\"\n\n$ dig TXT _dmarc.aezign.com.au +short\n\n\"v=DMARC1;p=quarantine;sp=quarantine;adkim=r;aspf=r\"\n\n$ dig TXT aezign.com.au-2026._domainkey.aezign.com.au +short\n\n\"v=DKIM1; h=sha256; k=rsa; s=email; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzL04yXZgB72YkoxS+tLK//aWx65TS4UA3F0qJ7el68SEuD4ehmg+61Ta9iS31H6U074dnjyoPDeaiGBa7ToTNCtiIts4/ghD/8nrENROE6hQAwRmTK18ODDHrRDW73hWe6Dg4cK5vmXi82/wWRZU9SDKbme28IE9uCVir3lCkKYLs1\" \"j16gR1Sjqr6a2+3o+EeVXnLJ4wXmJMm7KCIdn7zv0t9Z1eYcw672PdpYPAMpGb8uUsgaDBsNSpTcupPkz4SWj6TrOB80CPHjWseVY8EOJeRsNKQ/8LFoQEBl4Rxtb3HAmu4UIxSZ4QMVOLnXz67e85mA5XjcNIsVMzaWaowwIDAQAB\"</pre><!--]--><!----><p>As we can see, this matches, which means that the nameservers for <code>aezign.com.au</code> are correct and the DNS records are what we intend them to be.</p><p>Note that if you've recently changed the nameserver or DNS records for your domain, it can take anywhere between 10 seconds and 24 hours for the changes to take effect and propagate across the different DNS servers worldwide. Tools like <a href=\"https://dnschecker.org\">dnschecker.org</a> can check your records on different DNS servers worldwide to see if they're reflecting your changes. The reason for this is caching: DNS servers like <code>1.1.1.1</code> will cache results so it doesn't have to do the full resolution process every time, and uses the Time-To-Live (TTL) you configure in your DNS records as a guideline for caching duration.</p></article><!----><!--]-->",
            "url": "https://aezign.com.au/resources/how-dns-and-nameservers-work",
            "title": "A Brief Explanation of DNS and Nameservers",
            "summary": "Explore DNS, a part of the backbone behind the modern internet, how it works with nameservers, and how to ensure your website's DNS is set up correctly.",
            "image": "https://aezign.com.au/_app/immutable/assets/card-how-dns-and-nameservers-work.DCvo5pNt.jpg",
            "date_modified": "2026-09-28T00:00:00.000Z",
            "date_published": "2026-09-28T00:00:00.000Z",
            "author": {
                "name": "Maytham Alsudany",
                "url": "https://maytham.aezign.au"
            }
        }
    ]
}