InfraNestInfraNest
DNS

Authoritative DNS Server

An authoritative DNS server holds the actual zone data for a domain and answers DNS queries directly from its own records, not from cache.

An authoritative DNS server is a nameserver that holds the official, configured zone file for one or more domains and answers DNS queries directly from its stored records rather than from cached data. Its responses include the "AA" (Authoritative Answer) flag in the DNS message header.

When you query an authoritative server for a record in its zone, you get the authoritative answer—the source of truth. Every domain has at least two authoritative nameservers for redundancy. Authority is delegated from the parent zone via NS records, and the parent zone often stores "glue" A/AAAA records pointing to the child nameserver's IP address to bootstrap the delegation.

Each DNS zone contains a SOA record that names the primary (master) authoritative server, along with a serial number used for zone transfers and synchronization. Secondary authoritative servers pull zone data from the primary using AXFR (zone transfer) requests and keep their copy in sync.

Common scenario: You set your domain's nameservers at your domain registrar to ns1.example.com and ns2.example.com. Those servers are now authoritative for your zone. When someone queries www.example.com, a DNS resolver asks your authoritative servers, not some other cached copy.

WarningDo not confuse authoritative servers with DNS resolvers. A resolver answers queries from cache or by asking other servers; an authoritative server answers only for zones it owns and always returns the source-of-truth answer.

Use DNS propagation tools to verify your records have reached authoritative servers worldwide.

Related terms

See it in context

InfraNest shows you your own records, zones and certificates, so the terms stop being abstract.

Free plan · No credit card required · Set up in minutes