What a response actually demonstrates
During an incident, first write down the exact question: full name, type, class, queried server, origin and time. Then separate what was requested from what was answered. RD represents a recursion request; RA advertises that capability. AA characterizes authority in the response, not application health. A capture containing the correct address can coexist with HTTP 503. Preserve the header and sections before reducing the observation to a single ticket line.
An empty answer has more than one meaning
Compare two results for the same name in an exercise. The first has NOERROR, no AAAA and SOA in authority, without an alias or referral: interpret absence of the requested type. The second has NOERROR, child-zone NS in authority and nameserver addresses in additional: identify a delegation. Both can show ANSWER: 0. That counter alone cannot distinguish missing data from a next resolution step. The decision must use the complete message and query context.
Follow the alias before assigning the failure
Imagine files.fund.test as the stable name for a file service. The answer contains its CNAME to ingest.fund.test and ends with NXDOMAIN. Recreating the same CNAME does not repair a missing target. Draw the chain, identify the final name and confirm which team controls the approved destination. Do not substitute an arbitrary available machine: the endpoint also needs the correct data, access and role. The support question becomes the intended target and the change that removed it.
Calculate a cached absence
In the exercise model, SOA has TTL 900 and MINIMUM 180. The negative answer starts with 180 seconds. If received at 09:00:00, 110 seconds remain at 09:01:10, without refresh or additional rules. Also distinguish AAAA NODATA from name NXDOMAIN: a type-specific absence does not prevent a valid A. These calculations describe an identified entry. They are not a global recovery promise and do not include application policies, serve-stale or resolver failure caching.
Practice and shift handover
Run the local runner and compare positive, nodata, nxdomain and aliasTargetMissing in evidence.json. For each output, write one supported conclusion and one that the data cannot support. For example, the fixture sends SOA and TTL but does not store entries in a recursive cache. In a handover, provide the reproducible query, interpretation and next bounded test. If SERVFAIL persists after repair, also consider failure caching and timers, documented in RFC 9520, rather than reclassifying it as nonexistence.
# From the project root; binds an ephemeral loopback port only
python3 content/labs/dns-evidence/run.py
# Inspect observations.nodata and observations.aliasTargetMissing
# in content/labs/dns-evidence/evidence.jsonFictional case: an ingestion job receives CNAME and NXDOMAIN. The operator preserves the message, confirms the removed target and routes a bounded correction to its owner without recreating the existing alias.
Common pitfalls
Avoid equating ANSWER: 0 with NXDOMAIN, interpreting RA as executed recursion, or treating portal TTL as a client’s remaining TTL.
Related topics: Resolver, authority, and client context · TTL, negative caching, and controlled change · DNS transport and DNSSEC validation
Read the full message, locate the name and type actually affected, and separate the DNS observation from application availability.
Reference: RFC 2308 · DNS RFC 1034/1035 with RFC 2181, 2308, 3596, 4033, 7766 and 8767; dig BIND 9.20