DNS & BIND 9 (Linuxhotel September 2026)
1 Course Notes and exercises
This page contains the course notes and exercise instructions for attendees of the online training DNS & BIND 9 (Linuxhotel - September 2026).
Click on images to zoom in.
1.1 Introduction
- what is your interest in DNS?
- what is your prior knowledge of DNS?
- what do you want to learn about DNS?
1.2 Virtual machines for the training lab
- User :
user - Password:
DNSandBIND - Root-Shell via
sudo -s
1.2.1 DNS Resolver (Amsterdam)
| NN | Name | IPv4 | SSH Access | Zone |
|---|---|---|---|---|
| 01 | Sebastian | 136.244.110.223 | dnsr01.dnslab.org | -- |
| 02 | Tino | 140.82.58.87 | dnsr02.dnslab.org | -- |
| 03 | Daniel | 209.250.253.241 | dnsr03.dnslab.org | -- |
| 04 | Thomas | 45.32.233.202 | dnsr04.dnslab.org | -- |
| 05 | Torben | 95.179.139.194 | dnsr05.dnslab.org | -- |
| 06 | Paolo | 45.32.238.77 | dnsr06.dnslab.org | -- |
| 07 | Trainer | 108.61.164.159 | dnsr07.dnslab.org | -- |
| 08 | Frei | 45.76.38.27 | dnsr08.dnslab.org | -- |
2 New terminology used in DNS & BIND
- The terms
masterandslavehave been used to describe primary and secondary authoritative DNS servers in the past.- However this terminology is wrong and misleading, for reasons discussed in the Internet Draft Terminology, Power, and Inclusive Language in Internet-Drafts and RFCs: https://tools.ietf.org/html/draft-knodel-terminology
- In this document, and in configuration examples, we are using the
new terms
primary(instead ofmaster) andsecondary(instead ofslave) whenever possible. - BIND 9 has started adopting the new terms with BIND 9.14, however
the transition is not complete, and some terms in configuration
statements still use the old terms. This will change with
future releases
- If you use an older version of BIND 9, please substitute the new terms for the older ones
- The old terminology will also be found in older books and standards documents (RFCs and Internet Drafts)
- DNS terminology can be confusing and is sometimes overloaded. RFC 8499 DNS terminology ( https://tools.ietf.org/html/rfc8499 ) tries to collect and document the current usage of DNS terminology.
3 DNS Basics - how the protocol works
3.1 from HOSTS.TXT to DNS
- RFC 226 "STANDARDIZATION OF HOST MNEUMONICS" in 1971-09 was the first standardization of a naming convention for hosts on on the ARPANET.
- From 1970-1991 the Stanford Research Institution-Network
Information Center was the information hub for the ARPANET
including maintaining
hosts.txt. - The
hosts.txtfile- Contained IP addresses and names of all of the hosts on the Internet
- Contained host information as well…
- Produced twice per week and available via FTP
- Changes, adds and deletes were sent via e-mail
3.2 the creation of DNS (Domain Name System)
- Problems with
hosts.txt- Maintained by a single entity
- Pulled (manually) from a single host
- Namespace collisions
- Consistency
- In 1983, it was determined that something had to be done

Davis Mills: RFC 799 (1981) - Internet Name Domains 
Jon Postel & Zaw-Sing Su: RFC 819 (1982) - The Domain Naming Convention for Internet User Applications 
Paul Mockapetris: RFC 882 & RFC 883 (1983) - DOMAIN NAMES - CONCEPTS and FACILITIES / DOMAIN NAMES - IMPLEMENTATION and SPECIFICATION - RFC 882 was obsoleted by RFC 1034 (1987-11) and RFC 883 was obsoleted by RFC 1035 (1987-11)
3.3 The DNS namespace
3.4 The DNS namespace
3.5 Nodes contain data
3.6 Node Label
3.7 Node Label
3.8 Domain Names
3.9 Domain Names
3.10 Domain Names
3.11 Domain Names
3.12 Domain
3.13 Subdomain
3.14 Why delegation?
HOSTS.TXTwas monolithic, one large file- The DNS system is hierarchical
- parts of the name space are delegated to the owners of the name
- every owner controls the part of the name space she is owning
- every owner can sub-delegate downwards
- delegation goes from parent domain to child domain
- owner of parent domain can revoke delegation (and re-delegate to a different owner)
3.15 Delegation
3.16 Delegation
3.17 Delegation
3.18 Internet DNS: Root-Zone, Top-Level-Domains, Second-Level Domains
- The DNS delegation in the Internet has a specific structure. Other DNS systems (like the DNS used in mobile phone roaming, or local private DNS systems) can have different delegation rules
- RFC 920 defined the original structure of DNS delegation from the root zone
3.18.1 Root-Zone
- The root-zone is the start of all DNS name resolution
- The root-zone is hosted on 13 logical authoritative DNS server
(Root-DNS-Server), named
a.root-servers.nettom.root-servers.net - many logical Root-DNS-Server are spread around the world with identical copies
- You can learn about the Root-DNS-Server system on https://root-servers.org/
- the content of the root-zone is public and can be loaded from some of the root-server systems
dig @f.root-servers.net AXFR .
3.18.2 Generic Top-Level-Domains
- RFC 920 created the original seven generic top-level-domains
- arpa generic top level domain (gTLD)
- Originally used as a transition device from
HOSTS.TXTto DNS - Now used for Internet infrastructure data, e.g. reverse lookup tree for IPv4 and IPv6 addresses:
- IPv4:
in-addr.arpa. - IPv6:
ip6.arpa.
- IPv4:
- Registry: IANA
- Originally used as a transition device from
- com generic top level domain (gTLD)
- Commercial entities
- Over 150 million subdomains
- Largest Top Level Domain by a factor of six. (2nd is cn:~21 million)
- Registry: Verisign
- edu generic top level domain (gTLD)
- mostly U.S. based, accredited postsecondary institutions
- thousands of subdomains (
berkeley.edu,havard.edu,stanford.edu…) - Registry: Educause (operated by VeriSign)
- gov generic top level domain (gTLD)
- (U.S. Federal) government entities
- hundreds of subdomains (
fbi.gov,gsa.gov,irs.gov… ) - Some U.S. federal agencies use
.fed.us.rather than.gov. - RFC 2146 (U.S. Government Internet Domain Names) defines the use of
.govgTLD - Registry: General Services Administration
- mil generic top level domain (gTLD)
- (U.S.) military entities
- few (public) subdomains (
af.mil,army.mil,navy.mil,usmc.mil… ) - Registry: Defense Information Systems Agency
- net generic top level domain (gTLD)
- formerly networking entities and components
- now a general purpose TLD with nearly 14 million subdomains
- the 4th most popular domain (after
com,cnandde) - Registry: Verisign
- org generic top level domain (gTLD)
- Generally noncommercial entities that do not fit in other categories
- Millions of subdomains (
isc.org,npr.org,pbs.org…) - Finances the Internet Society (ISOC), which itself is responsible for the IETF and IAB
- Registry: Public Interest Registry PIR (operated by Afilias)
3.18.3 Country-Code Top-Level-Domains
- in 1985 TLDs were reserved for every country
- Called country code top-level domains, or ccTLD (RFC 1591 "Domain Name System Structure and Delegation")
- They match the two-letter abbreviations in ISO-3166-1
- Two were delegated in 1985
- Some that once existed have been deleted (e.g.
.yuYugoslavia)
3.18.4 Special Use Top-Level-Domains
- RFC 2606 (1999 "Reserved Top Level DNS Names") and updates in RFC
6761 (2013 "Special-Use Domain Names") reserved 4 TLDs:
example: for use in examplesinvalid: for use in obviously invalid domain namestest: for use in testslocalhost: to avoid conflict with the use of the (single label) hostnamelocalhostin Unix/Linux systemsexample.com,example.netandexample.orgare also reserved..internalis a new reserved TLD that ICANN has reserved for internal use. This domain is similar to RFC 1918 private IPv4 addresses. (Internet Draft: A Top-level Domain for Private Use)
- Special use domains: pre-internet networks have used domain names
not registered (
.bitnet,.csnet,.uucp). Also newer technologies are using non-registered gTLDs:.onion,.exit: TOR privacy network.swift: SWIFTNet Mail.local: Zeroconf protocol (Apple Bonjour/Rendezvous, Unix/Linux Avahi)
- RFC 8375 - Special-Use Domain 'home.arpa.' defines the special
domain name
home.arpa.. This domain is intended for use inside private networks (similar to RFC 1918 IPv4 addresses). It should not be used in the Internet can be used in internal network DNS systems without risk of collisions with the Internet DNS name space. It is used in the Home Networking Control Protocol (HNCP) suite, but can also used for other cases, such as Microsoft Active Directory domains. - RFC 7050 - Discovery of the IPv6 Prefix Used for IPv6 Address
Synthesis and RFC 8880 - Special Use Domain Name 'ipv4only.arpa'
define the special domain name
ipv4only.arpa. This domain is being used in DNS64 clients on an IPv6-only network to detect the presence of DNS64 and for learning the IPv6 prefix used for protocol translation on the network. - Warning: do no use these reserved names in DNS, not even in a private network, as DNS software treats this domains differently
- IANA Registry for "special use domain names": https://www.iana.org/assignments/special-use-domain-names/special-use-domain-names.xml
3.18.5 New Top-Level-Domains
- in 1988, a new generic top-level domain was introduced:
int.intwas historically used for "Internet infrastructure databases" to replacearpa(for example used asip6.int.)- in 2000, the IAB decided to keep
arpaand useintfor international treaty-based organizations, United Nations agencies, observers at the UN
- Starting in 2000, ICANN allowed several new gTLDs to be created:
info,name,pro,aero,tel,museum,coop,biz…- Today, ICANN policies allow new gTLDs for anyone able to pay:
.xyz,.nrw,.sap,.sport,.search,.google,.etisalat,.grocery…
- Today, ICANN policies allow new gTLDs for anyone able to pay:
3.19 DNS Name Resolution
- DNS Query - what the client sends
p>
- DNS Name Resolution
p>
3.20 Caching
- DNS Resolver caching
p>
3.21 Negative Caching
NXDOMAIN- the domain name does not exist.NOERROR/NODATA- the domain name exists, but not the RR type. AKA:NOERROR/NOANSWER.- For
NXDOMAINandNOERROR/NODATA, the zone'sSOAis returned in the authoritative section. - The negative TTL is the minimum of SOA's TTL and the SOA's RDATA MIN field. (RFC 2308)
- BIND's default max-ncache-ttl is 10800 seconds (3 hrs).
3.22 how DNS data is stored and sent / Anatomy of DNS resource records
- DNS Data is stored and sent in units of "DNS resource records" (or DNS RR)
- The fields of DNS resource records
- owner: the domain name that owns the data. This is the index to the DNS database
- TTL: the Time-to-Live, the time in seconds that this DNS data is guaranteed to be valid. This is used to timeout data in caches. It is also sometimes used by applications.
- Class: The network infrastructure this data is useful in. In TCP/IP networks, this is typically IN for Internet protocol.
- Type: The type of data, it can be A for IPv4 Address records, AAAA for IPv6 Addresses, TXT for free form text, NS for nameserver entries and many more
- RData: record data, the data that is attached to the domain name. Depending on the type of record, the RData can have one to many fields
- we find DNS resource records
- in DNS zone database files on authoritative DNS servers
- in the caches of DNS resolver servers
- in the output of a DNS query and troubleshooting tools
- on the wire, the data is transported in binary form (non readable for humans)
- DNS tools convert the DNS resource records from binary form into text form for human consumption
3.23 Resource Record Sets
- A Resource Record Set (RRSet) is all RRs with identical: owner name, network class, TTL, and record type
- Each RR of a RRSet has different RDATA.
- A RRSet is not-explicit, and the RRs do not have to be contiguous in the zone file.
- All RRs in a RRSet are sent in a query response.
- They may be returned in any order.
- The TTLs of all RRs in a RRSet must be identical.
- Otherwise caching can lead to a single point of failure.
- BIND enforces this by using the first seen TTL of the RRs.
- A valid DNS resource record set
| Owner | TTL | Class | Type | RData |
|---|---|---|---|---|
| example.com. | 86400 | IN | NS | a.iana-servers.net. |
| example.com. | 86400 | IN | NS | b.iana-servers.net. |
- An invalid DNS resource record set (different TTLs, duplicate record data)
| Owner | TTL | Class | Type | RData |
|---|---|---|---|---|
| example.invalid. | 86400 | IN | NS | a.iana-servers.net. |
| example.invalid. | 3600 | IN | NS | b.iana-servers.net. |
| example.invalid. | 7200 | IN | NS | b.iana-servers.net. |
4 Master File Format
- The master file format defines DNS zone storage.
- Master File Format is defined in RFC 1035.
- Many authoritative server implementations, including BIND, support other storage.
- e.g. Databases, Active Directory, etc.
- Most minimally support entering data in Master File Format.
4.1 A Minimal Zone
- A zone must have:
- one SOA record
- at least one NS record
- We’ll show all RRs in their complete form.
4.2 The Start of Authority Record (SOA)
- A
SOARR defines configurations parameters for a zone. - The owner name of a SOA RR matches the zone's name.
- The SOA must be the first RR in a zone file.
- The SOA is an internal RR that exists for DNS' own functionality.
- Four SOA RDATA fields are information for secondaries.
- One RDATA field is for resolvers.
dnslab.org. 86400 IN SOA ( dns1.dnslab.org. ; MNAME: primary server hostmaster.dnslab.org. ; RNAME: responsible person 2018061901 ; SERIAL 900 ; REFRESH 300 ; RETRY 604800 ; EXPIRE 900 ) ; negTTL (officially:MINIMUM)
4.3 SOA record and zone transfer
- A Day in the Life of two DNS Servers
p>
4.4 Scaled Values
- TTLs and the SOA timers can be entered as scaled values in most modern authoritative servers.
- An integer value followed by:
- s, for seconds
- m, for minutes
- h, for hours
- d, for days
- w, for weeks
- An integer value followed by:
- Example:
1w2d5h3m20s = 1 week + 2 days + 5 hours + 3 minutes + 20 seconds = 795,800 seconds
4.5 SOA Recommended Values
SOURCE: https://www.ripe.net/ripe/meetings/ripe-55/presentations/koch-ripe203bis.pdf
"These recommendations are aimed at small and stable DNS zones. There are many legitimate reasons to use different values…"
4.6 Master File Format Comments
- Comments in master file format begin with a semicolon (
;) and extend to the end of the line. - Example:
; important router addresses router1.example.com. 3600 IN A 192.0.2.1 ; gateway1 router2.example.com. 3600 IN A 192.0.2.100 ; tunnel GW
4.7 Extending RRs over Multiple Lines
- A RR must be written on one line.
- Records can be written over multiple lines using parentheses.
- The parentheses can be at any whitespace in the RR.
- The opening parenthesis must be on the first line.
- Example 1
example.com. 86400 IN SOA dns1.example.com. ( hostmaster.example.com. 2012111701 ; serial 86400 ; refresh 7200 ; retry 3600000 ; expire 3600 ) ; negTTL - Example 2
example.com. ( 86400 IN SOA dns1.example.com. hostmaster.example.com. 2012111701 ; serial 86400 ; refresh 7200 ; retry 3600000 ; expire 3600 ) ; negTTL - Example 3
example.com. 86400 IN SOA ( dns1.example.com. hostmaster.example.com. 2012111701 86400 7200 3600000 3600 ) - Example 4
example.com. 86400 IN SOA ns1.test. admin.example. ( 2012111701 86400 7200 3600000 3600 )
4.8 Zone File: Syntax & Integrity Check
- BIND includes a tool to check a zone file for syntax errors and required missing data (e.g. no NS RR).
- It is recommended to always check a zone file and correct all errors before having named (re)load it.
- Syntax:
named-checkzone <zonename> <filename>% named-checkzone example.com example.com.zonefile zone example.com/IN: loaded serial 2018072901 OK
4.9 Quiz
- Spot the many errors: What’s wrong with this SOA record? Write your
findings in the chat
example.com 3600 IS SOA ( hostmaster.example.com ns1.example.com 20180101 // serial 3600 // retry 3600 // refresh 3600 // expire 3600 // negTTL )
4.9.1 Solution
- Domain names are not FQDN (probable error).
- CLASS: IS -> IN
- email & mname probably swapped.
- email & mname not FQDNs.
- comments wrong.
- serial probably two digits too few.
- closing parenthesis commented out
- Retry, refresh, expire timers illogical.
- Retry and Refresh swapped (in the comments)
5 Fundamental DNS Resource Records
5.1 The NS Record
- The
NSrecord has two functions.- To define the authoritative servers for a zone.
- To delegate to authoritative servers for a sub-domain.
- Like the SOA, the NS is an internal RR that exists for DNS' functionality.
5.1.1 Rules for the NS Record
- Like SOA RRs, the NS owner name is the name of the zone.
- The RDATA contains the domain name (not the IP Address) of an authoritative server for the zone.
- Zones should have more than one authoritative server, and therefore more than one NS RR (making a RRSet).
- The delegation NS RRs (in the parent zone) and the NS RR in the zone should always match. see Raffaele Sommese - When Parents and Children Disagree: Diving into DNS Delegation Inconsistency (RIPE 80)
p>
5.1.2 Glue Records
- Glue records are used to solve the “chicken-and-egg” problem of DNS delegation.
- Glue is required when a zone is delegated to a server whose domain name is in the delegated zone.
p>
5.2 IPv4 Address record
- An
ARR maps a domain name to an IPv4 addresswww.example.com. 86400 IN A 192.0.2.10
- One domain name can map to multiple
ARRs.host.example.com. 3600 IN A 192.0.2.10 host.example.com. 3600 IN A 10.0.10.2 host.example.com. 3600 IN A 172.16.1.12
- The server returns all addresses (a RRSet).
- When a stub resolver returns multiple addresses to an application,
the application should do something intelligent.
- Many don’t :(
5.3 The IPv6 Address Record (AAAA)
- The
AAAArecord maps a domain name to an IPv6 addresswww.example.com. 86400 IN AAAA 2001:db8:110:100:20:102f:ffeb:5380
- Many applications query for a
AAAARR before falling back to an A RR. - When they get a response for the
AAAAquery, most will not try to lookup an IPv4 address. - If the successfully resolved
AAAAdoesn't lead to an active server, an application will likely fail. - So if a
AAAAaddress exists, it must be available. - The Happy Eyeball protocol addresses the problem when present: RFC 8305: Happy Eyeballs Version 2: Better Connectivity Using Concurrency
5.4 The HTTPS Record
- The
HTTPSrecord is a relativly new record. It's type number is 65 (aka TYPE65)- It has been first observed "in the wild" in Summer 2020
- It is being used in the new Apple operating systems (iOS, iPadOS, macOS) since fall 2020
- It is now the 3rd most queried DNS record in the Internet (after
AandAAAA)
- The HTTPS and SVCB records are discussed in RFC 9460 "Service binding and parameter specification via the DNS (DNS SVCB and HTTPS RRs)" https://datatracker.ietf.org/doc/html/rfc9460
- The
HTTPSdelivers connection information for an HTTPS service- IPv4-Addresses of the service
- IPv6-Addresses of the server
- The public key of the server to be used to initiate an encrypted TLS "client hello"
- Protocol selection: HTTP/2 (TCP) or HTTP/3 (QUIC)
- One or more DoH-Resolver for the service
- Example of a
HTTPSRecord for a service offering HTTP/2 and HTTP/3 (preferred)
example.com 3600 IN HTTPS 1 . alpn=”h3,h2”
- Example of a
HTTPSRecord for a service with both IPv4 and IPv6 Addresses
example.com 3600 IN HTTPS 1 . alpn=”h3,h2” ipv4hint=”192.0.2.1” ipv6hint=”2001:db8::1”
- Benefits of the HTTPS records
- Browser don't need to request explicit IPv6 and IPv4 Addresses (faster connection)
- The
HTTPSRecords is a signal to the web-browser to only allow TLS secured/encrypted connections for this domain name. This prevents downgrade attacks - With the
HTTPSRecord it is possible to create Domain-Alias definitions for whole zones (not possible with theCNAMERecord)
- The BIND 9 DNS server and tools (
dig,host) support theHTTPSrecord since version 9.16.21 (September 2021)