← DNS: understand and diagnose resolution
04 / 5 · 18 MIN

NXDOMAIN, NODATA, SERVFAIL, and timeout

Interpret the response before choosing mitigation.

Concept and mechanism

A timeout means no answer was received within the observed limit. This differs from receiving an answer declaring nonexistence. NXDOMAIN indicates that the queried name does not exist in the response context. NODATA describes an answer without the requested record type for an existing name and is not a separate RCODE named NODATA. SERVFAIL indicates query-processing failure with several possible causes. The code guides investigation but does not replace context and comparison.

Guided application

In an authorized terminal, a directed dig query selects server, name, and type. Record status, flags, answer and authority sections, server, and timing. Compare the same query from relevant origins before changing the zone. For timeout, investigate resolver reachability and transport; for NXDOMAIN, confirm name, view, and negative cache; for SERVFAIL, inspect resolution path and validation. Once the name resolves, move on to application connection and protocol. Diagnosis should move layers when evidence supports it.

IN PRACTICE

dig @192.0.2.53 api.example A is illustrative and uses documentation addresses. It does not prove the real application uses that resolver; confirm effective client configuration.

Common pitfalls

Treating timeout as nonexistence; treating SERVFAIL as proof of one specific cause; clearing caches before recording evidence.

Related topics: DNS transport and DNSSEC validation · Resolver, authority, and client context

Take this idea with you

Response type determines the next hypothesis to test.

Create account

Reference: ISC BIND 9: dig manual · DNS RFC 1034/1035 with RFC 2181, 2308, 3596, 4033, 7766 and 8767; dig BIND 9.20