DNS & BIND 9 (Linuxhotel September 2026)

1 Course Notes and exercises

This page contains the course notes and exercise instructions for attendees of the online training DNS & BIND 9 (Linuxhotel - September 2026).

Click on images to zoom in.

1.1 Introduction

  • what is your interest in DNS?
  • what is your prior knowledge of DNS?
  • what do you want to learn about DNS?

1.2 Virtual machines for the training lab

  • User : user
  • Password: DNSandBIND
  • Root-Shell via sudo -s

1.2.1 DNS Resolver (Amsterdam)

NN Name IPv4 SSH Access Zone
01 Sebastian 136.244.110.223 dnsr01.dnslab.org --
02 Tino 140.82.58.87 dnsr02.dnslab.org --
03 Daniel 209.250.253.241 dnsr03.dnslab.org --
04 Thomas 45.32.233.202 dnsr04.dnslab.org --
05 Torben 95.179.139.194 dnsr05.dnslab.org --
06 Paolo 45.32.238.77 dnsr06.dnslab.org --
07 Trainer 108.61.164.159 dnsr07.dnslab.org --
08 Frei 45.76.38.27 dnsr08.dnslab.org --

2 New terminology used in DNS & BIND

  • The terms master and slave have been used to describe primary and secondary authoritative DNS servers in the past.
  • In this document, and in configuration examples, we are using the new terms primary (instead of master) and secondary (instead of slave) whenever possible.
  • BIND 9 has started adopting the new terms with BIND 9.14, however the transition is not complete, and some terms in configuration statements still use the old terms. This will change with future releases
    • If you use an older version of BIND 9, please substitute the new terms for the older ones
  • The old terminology will also be found in older books and standards documents (RFCs and Internet Drafts)
  • DNS terminology can be confusing and is sometimes overloaded. RFC 8499 DNS terminology ( https://tools.ietf.org/html/rfc8499 ) tries to collect and document the current usage of DNS terminology.

3 DNS Basics - how the protocol works

3.1 from HOSTS.TXT to DNS

0101-arpanet-1969.png

0102-Internet-1983.png

  • From 1970-1991 the Stanford Research Institution-Network Information Center was the information hub for the ARPANET including maintaining hosts.txt.
  • The hosts.txt file
    • Contained IP addresses and names of all of the hosts on the Internet
    • Contained host information as well…
    • Produced twice per week and available via FTP
    • Changes, adds and deletes were sent via e-mail

3.2 the creation of DNS (Domain Name System)

  • Problems with hosts.txt
    • Maintained by a single entity
    • Pulled (manually) from a single host
    • Namespace collisions
    • Consistency
  • In 1983, it was determined that something had to be done
    0103-David-Mills.png Davis Mills: RFC 799 (1981) - Internet Name Domains
    0104-Jon-Postel.png Jon Postel & Zaw-Sing Su: RFC 819 (1982) - The Domain Naming Convention for Internet User Applications
    0105-Paul-Mockapetris.png Paul Mockapetris: RFC 882 & RFC 883 (1983) - DOMAIN NAMES - CONCEPTS and FACILITIES / DOMAIN NAMES - IMPLEMENTATION and SPECIFICATION
  • RFC 882 was obsoleted by RFC 1034 (1987-11) and RFC 883 was obsoleted by RFC 1035 (1987-11)

3.3 The DNS namespace

dns-namespace01.png

Figure 3: The DNS Namespace is often drawn as an inverted tree

3.4 The DNS namespace

dns-namespace01.png

Figure 4: The DNS Namespace can be up to 127 levels deep

3.5 Nodes contain data

dns-namespace02.png

3.6 Node Label

dns-namespace03.png

Figure 6: Node labels can be zero to 63 bytes long

3.7 Node Label

dns-namespace04.png

Figure 7: Node label are unique for sibling nodes

3.8 Domain Names

domainnames01.png

3.9 Domain Names

domainnames02.png

3.10 Domain Names

domainnames03.png

3.11 Domain Names

domainnames04.png

3.12 Domain

domain01.png

Figure 12: A domain is a subtree of the DNS namespace

3.13 Subdomain

domain02.png

Figure 13: A subdomain is a domain a domain whose apex is inside another domain

3.14 Why delegation?

  • HOSTS.TXT was monolithic, one large file
  • The DNS system is hierarchical
  • parts of the name space are delegated to the owners of the name
  • every owner controls the part of the name space she is owning
  • every owner can sub-delegate downwards
  • delegation goes from parent domain to child domain
  • owner of parent domain can revoke delegation (and re-delegate to a different owner)

3.15 Delegation

delegation01.png

Figure 14: Delegation creates Zones

3.16 Delegation

delegation02.png

Figure 15: The apex node names a zone

3.17 Delegation

delegation03.png

Figure 16: The apex node names a zone

3.18 Internet DNS: Root-Zone, Top-Level-Domains, Second-Level Domains

  • The DNS delegation in the Internet has a specific structure. Other DNS systems (like the DNS used in mobile phone roaming, or local private DNS systems) can have different delegation rules
  • RFC 920 defined the original structure of DNS delegation from the root zone

3.18.1 Root-Zone

  • The root-zone is the start of all DNS name resolution
  • The root-zone is hosted on 13 logical authoritative DNS server (Root-DNS-Server), named a.root-servers.net to m.root-servers.net
  • many logical Root-DNS-Server are spread around the world with identical copies
  • You can learn about the Root-DNS-Server system on https://root-servers.org/
  • the content of the root-zone is public and can be loaded from some of the root-server systems
dig @f.root-servers.net AXFR .

3.18.2 Generic Top-Level-Domains

  • RFC 920 created the original seven generic top-level-domains

0116-genreic-TLD.png

  • arpa generic top level domain (gTLD)
    • Originally used as a transition device from HOSTS.TXT to DNS
    • Now used for Internet infrastructure data, e.g. reverse lookup tree for IPv4 and IPv6 addresses:
      • IPv4: in-addr.arpa.
      • IPv6: ip6.arpa.
    • Registry: IANA
  • com generic top level domain (gTLD)
    • Commercial entities
    • Over 150 million subdomains
    • Largest Top Level Domain by a factor of six. (2nd is cn:~21 million)
    • Registry: Verisign
  • edu generic top level domain (gTLD)
    • mostly U.S. based, accredited postsecondary institutions
    • thousands of subdomains (berkeley.edu, havard.edu, stanford.edu …)
    • Registry: Educause (operated by VeriSign)
  • gov generic top level domain (gTLD)
    • (U.S. Federal) government entities
    • hundreds of subdomains (fbi.gov, gsa.gov, irs.gov … )
    • Some U.S. federal agencies use .fed.us. rather than .gov.
    • RFC 2146 (U.S. Government Internet Domain Names) defines the use of .gov gTLD
    • Registry: General Services Administration
  • mil generic top level domain (gTLD)
    • (U.S.) military entities
    • few (public) subdomains (af.mil, army.mil, navy.mil, usmc.mil … )
    • Registry: Defense Information Systems Agency
  • net generic top level domain (gTLD)
    • formerly networking entities and components
    • now a general purpose TLD with nearly 14 million subdomains
    • the 4th most popular domain (after com, cn and de)
    • Registry: Verisign
  • org generic top level domain (gTLD)
    • Generally noncommercial entities that do not fit in other categories
    • Millions of subdomains (isc.org, npr.org, pbs.org …)
    • Finances the Internet Society (ISOC), which itself is responsible for the IETF and IAB
    • Registry: Public Interest Registry PIR (operated by Afilias)

3.18.3 Country-Code Top-Level-Domains

0117-ccTLDs.png

3.18.4 Special Use Top-Level-Domains

  • RFC 2606 (1999 "Reserved Top Level DNS Names") and updates in RFC 6761 (2013 "Special-Use Domain Names") reserved 4 TLDs:
    • example: for use in examples
    • invalid: for use in obviously invalid domain names
    • test: for use in tests
    • localhost: to avoid conflict with the use of the (single label) hostname localhost in Unix/Linux systems
    • example.com, example.net and example.org are also reserved.
    • .internal is a new reserved TLD that ICANN has reserved for internal use. This domain is similar to RFC 1918 private IPv4 addresses. (Internet Draft: A Top-level Domain for Private Use)
  • Special use domains: pre-internet networks have used domain names not registered (.bitnet, .csnet, .uucp). Also newer technologies are using non-registered gTLDs:
    • .onion, .exit: TOR privacy network
    • .swift: SWIFTNet Mail
    • .local: Zeroconf protocol (Apple Bonjour/Rendezvous, Unix/Linux Avahi)
  • RFC 8375 - Special-Use Domain 'home.arpa.' defines the special domain name home.arpa.. This domain is intended for use inside private networks (similar to RFC 1918 IPv4 addresses). It should not be used in the Internet can be used in internal network DNS systems without risk of collisions with the Internet DNS name space. It is used in the Home Networking Control Protocol (HNCP) suite, but can also used for other cases, such as Microsoft Active Directory domains.
  • RFC 7050 - Discovery of the IPv6 Prefix Used for IPv6 Address Synthesis and RFC 8880 - Special Use Domain Name 'ipv4only.arpa' define the special domain name ipv4only.arpa. This domain is being used in DNS64 clients on an IPv6-only network to detect the presence of DNS64 and for learning the IPv6 prefix used for protocol translation on the network.
  • Warning: do no use these reserved names in DNS, not even in a private network, as DNS software treats this domains differently
  • IANA Registry for "special use domain names": https://www.iana.org/assignments/special-use-domain-names/special-use-domain-names.xml

3.18.5 New Top-Level-Domains

  • in 1988, a new generic top-level domain was introduced: int
    • .int was historically used for "Internet infrastructure databases" to replace arpa (for example used as ip6.int.)
    • in 2000, the IAB decided to keep arpa and use int for international treaty-based organizations, United Nations agencies, observers at the UN
  • Starting in 2000, ICANN allowed several new gTLDs to be created: info, name, pro, aero, tel, museum, coop, biz …
    • Today, ICANN policies allow new gTLDs for anyone able to pay: .xyz, .nrw, .sap, .sport, .search, .google, .etisalat, .grocery …

3.19 DNS Name Resolution

  • DNS Query - what the client sends

  • DNS Name Resolution

3.20 Caching

  • DNS Resolver caching

3.21 Negative Caching

  • NXDOMAIN - the domain name does not exist.
  • NOERROR/NODATA - the domain name exists, but not the RR type. AKA: NOERROR/NOANSWER.
  • For NXDOMAIN and NOERROR/NODATA, the zone's SOA is returned in the authoritative section.
  • The negative TTL is the minimum of SOA's TTL and the SOA's RDATA MIN field. (RFC 2308)
  • BIND's default max-ncache-ttl is 10800 seconds (3 hrs).

3.22 how DNS data is stored and sent / Anatomy of DNS resource records

  • DNS Data is stored and sent in units of "DNS resource records" (or DNS RR)

0115-DNS-Resource-Record.png

  • The fields of DNS resource records
    • owner: the domain name that owns the data. This is the index to the DNS database
    • TTL: the Time-to-Live, the time in seconds that this DNS data is guaranteed to be valid. This is used to timeout data in caches. It is also sometimes used by applications.
    • Class: The network infrastructure this data is useful in. In TCP/IP networks, this is typically IN for Internet protocol.
    • Type: The type of data, it can be A for IPv4 Address records, AAAA for IPv6 Addresses, TXT for free form text, NS for nameserver entries and many more
    • RData: record data, the data that is attached to the domain name. Depending on the type of record, the RData can have one to many fields
  • we find DNS resource records
    • in DNS zone database files on authoritative DNS servers
    • in the caches of DNS resolver servers
    • in the output of a DNS query and troubleshooting tools
  • on the wire, the data is transported in binary form (non readable for humans)
  • DNS tools convert the DNS resource records from binary form into text form for human consumption

3.23 Resource Record Sets

  • A Resource Record Set (RRSet) is all RRs with identical: owner name, network class, TTL, and record type
  • Each RR of a RRSet has different RDATA.
  • A RRSet is not-explicit, and the RRs do not have to be contiguous in the zone file.
  • All RRs in a RRSet are sent in a query response.
    • They may be returned in any order.
  • The TTLs of all RRs in a RRSet must be identical.
    • Otherwise caching can lead to a single point of failure.
    • BIND enforces this by using the first seen TTL of the RRs.
  • A valid DNS resource record set
Owner TTL Class Type RData
example.com. 86400 IN NS a.iana-servers.net.
example.com. 86400 IN NS b.iana-servers.net.
  • An invalid DNS resource record set (different TTLs, duplicate record data)
Owner TTL Class Type RData
example.invalid. 86400 IN NS a.iana-servers.net.
example.invalid. 3600 IN NS b.iana-servers.net.
example.invalid. 7200 IN NS b.iana-servers.net.

4 Master File Format

  • The master file format defines DNS zone storage.
    • Master File Format is defined in RFC 1035.
    • Many authoritative server implementations, including BIND, support other storage.
      • e.g. Databases, Active Directory, etc.
      • Most minimally support entering data in Master File Format.

0115-DNS-Resource-Record.png

4.1 A Minimal Zone

  • A zone must have:
    • one SOA record
    • at least one NS record
  • We’ll show all RRs in their complete form.

4.2 The Start of Authority Record (SOA)

  • A SOA RR defines configurations parameters for a zone.
  • The owner name of a SOA RR matches the zone's name.
  • The SOA must be the first RR in a zone file.
  • The SOA is an internal RR that exists for DNS' own functionality.
  • Four SOA RDATA fields are information for secondaries.
  • One RDATA field is for resolvers.
dnslab.org. 86400 IN SOA (
   dns1.dnslab.org.            ; MNAME: primary server
   hostmaster.dnslab.org.      ; RNAME: responsible person
   2018061901                  ; SERIAL
   900                         ; REFRESH
   300                         ; RETRY
   604800                      ; EXPIRE
   900 )                       ; negTTL (officially:MINIMUM)

4.3 SOA record and zone transfer

  • A Day in the Life of two DNS Servers

4.4 Scaled Values

  • TTLs and the SOA timers can be entered as scaled values in most modern authoritative servers.
    • An integer value followed by:
      • s, for seconds
      • m, for minutes
      • h, for hours
      • d, for days
      • w, for weeks
  • Example:
    1w2d5h3m20s =
      1 week + 2 days + 5 hours + 3 minutes + 20 seconds =
      795,800 seconds
    

4.5 SOA Recommended Values

0505-soa-recommended-values.png SOURCE: https://www.ripe.net/ripe/meetings/ripe-55/presentations/koch-ripe203bis.pdf

"These recommendations are aimed at small and stable DNS zones. There are many legitimate reasons to use different values…"

4.6 Master File Format Comments

  • Comments in master file format begin with a semicolon (;) and extend to the end of the line.
  • Example:
    ; important router addresses
    router1.example.com.  3600 IN A 192.0.2.1   ; gateway1
    router2.example.com.  3600 IN A 192.0.2.100 ; tunnel GW
    

4.7 Extending RRs over Multiple Lines

  • A RR must be written on one line.
  • Records can be written over multiple lines using parentheses.
  • The parentheses can be at any whitespace in the RR.
  • The opening parenthesis must be on the first line.
  • Example 1
    example.com.  86400  IN SOA  dns1.example.com. (
                             hostmaster.example.com.
                             2012111701  ; serial
                             86400       ; refresh
                             7200        ; retry
                             3600000     ; expire
                             3600 )      ; negTTL
    
  • Example 2
    example.com. ( 86400  IN SOA  dns1.example.com.
                             hostmaster.example.com.
                             2012111701  ; serial
                             86400       ; refresh
                             7200        ; retry
                             3600000     ; expire
                             3600 )      ; negTTL
    
  • Example 3
    example.com.  86400  IN SOA  ( dns1.example.com.
                             hostmaster.example.com.
                             2012111701 86400 7200
                             3600000 3600 )
    
  • Example 4
    example.com.  86400  IN SOA ns1.test. admin.example. (
                        2012111701 86400 7200 3600000 3600 )
    

4.8 Zone File: Syntax & Integrity Check

  • BIND includes a tool to check a zone file for syntax errors and required missing data (e.g. no NS RR).
  • It is recommended to always check a zone file and correct all errors before having named (re)load it.
  • Syntax: named-checkzone <zonename> <filename>
    % named-checkzone example.com example.com.zonefile
    zone example.com/IN: loaded serial 2018072901  OK
    

4.9 Quiz

  • Spot the many errors: What’s wrong with this SOA record? Write your findings in the chat
    example.com  3600 IS SOA (
               hostmaster.example.com
               ns1.example.com
               20180101   // serial
               3600       // retry
               3600       // refresh
               3600       // expire
               3600       // negTTL )
    

4.9.1 Solution

  • Domain names are not FQDN (probable error).
  • CLASS: IS -> IN
  • email & mname probably swapped.
  • email & mname not FQDNs.
  • comments wrong.
  • serial probably two digits too few.
  • closing parenthesis commented out
  • Retry, refresh, expire timers illogical.
  • Retry and Refresh swapped (in the comments)

5 Fundamental DNS Resource Records

5.1 The NS Record

  • The NS record has two functions.
    • To define the authoritative servers for a zone.
    • To delegate to authoritative servers for a sub-domain.
  • Like the SOA, the NS is an internal RR that exists for DNS' functionality.

0506-ns-record.png

5.1.1 Rules for the NS Record

5.1.2 Glue Records

  • Glue records are used to solve the “chicken-and-egg” problem of DNS delegation.
  • Glue is required when a zone is delegated to a server whose domain name is in the delegated zone.

5.2 IPv4 Address record

  • An A RR maps a domain name to an IPv4 address
    www.example.com.  86400 IN A 192.0.2.10
    
  • One domain name can map to multiple A RRs.
    host.example.com.    3600 IN A 192.0.2.10
    host.example.com.    3600 IN A 10.0.10.2
    host.example.com.    3600 IN A 172.16.1.12
    
  • The server returns all addresses (a RRSet).
  • When a stub resolver returns multiple addresses to an application, the application should do something intelligent.
    • Many don’t :(

5.3 The IPv6 Address Record (AAAA)

  • The AAAA record maps a domain name to an IPv6 address
    www.example.com.  86400 IN AAAA 2001:db8:110:100:20:102f:ffeb:5380
    
  • Many applications query for a AAAA RR before falling back to an A RR.
  • When they get a response for the AAAA query, most will not try to lookup an IPv4 address.
  • If the successfully resolved AAAA doesn't lead to an active server, an application will likely fail.
  • So if a AAAA address exists, it must be available.
  • The Happy Eyeball protocol addresses the problem when present: RFC 8305: Happy Eyeballs Version 2: Better Connectivity Using Concurrency

5.4 The HTTPS Record

  • The HTTPS record is a relativly new record. It's type number is 65 (aka TYPE65)
    • It has been first observed "in the wild" in Summer 2020
    • It is being used in the new Apple operating systems (iOS, iPadOS, macOS) since fall 2020
    • It is now the 3rd most queried DNS record in the Internet (after A and AAAA)
  • The HTTPS delivers connection information for an HTTPS service
    • IPv4-Addresses of the service
    • IPv6-Addresses of the server
    • The public key of the server to be used to initiate an encrypted TLS "client hello"
    • Protocol selection: HTTP/2 (TCP) or HTTP/3 (QUIC)
    • One or more DoH-Resolver for the service
  • Example of a HTTPS Record for a service offering HTTP/2 and HTTP/3 (preferred)
example.com 3600 IN HTTPS 1 . alpn=”h3,h2”
  • Example of a HTTPS Record for a service with both IPv4 and IPv6 Addresses
example.com 3600 IN HTTPS 1 . alpn=”h3,h2” ipv4hint=”192.0.2.1” ipv6hint=”2001:db8::1”
  • Benefits of the HTTPS records
    • Browser don't need to request explicit IPv6 and IPv4 Addresses (faster connection)
    • The HTTPS Records is a signal to the web-browser to only allow TLS secured/encrypted connections for this domain name. This prevents downgrade attacks
    • With the HTTPS Record it is possible to create Domain-Alias definitions for whole zones (not possible with the CNAME Record)
  • The BIND 9 DNS server and tools (dig, host) support the HTTPS record since version 9.16.21 (September 2021)