# Anyone know much about DNS?

**URL:** <https://boards.straightdope.com/t/anyone-know-much-about-dns/52529>\
**Category:** Factual Questions\
**Created:** [January 31, 2001, 6:27am UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529 "2001-01-31T06:27:56Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [January 31, 2001, 6:27am UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/1 "2001-01-31T06:27:56Z")

</div>

I have a domain, [friedo.com](http://friedo.com). Some people can see [www.friedo.com](http://www.friedo.com), and others can’t. It seems that some people’s nameservers were still pointing at an obsolete address for it (129.21.107.160) when it should be pointing at 64.27.106.52. I couldn’t figure out exactly why this is happening. For example, if I do an nslookup, it seems correct.

```auto

bash-2.02$ nslookup
Default Server: localhost
Address: 127.0.0.1

> friedo.com
Server: localhost
Address: 127.0.0.1

Non-authoritative answer:
Name: friedo.com
Address: 64.27.106.52

> www.friedo.com
Server: localhost
Address: 127.0.0.1

Name: www.friedo.com
Address: 64.27.106.52

```

And yet, some people reported it still pointing to the old address (which, btw, results in a connection refused error because that address is in a building that doesn’t exist anymore. 🙂 )

On a whim, I tried a WHOIS, and look what I found.

```auto

bash-2.02$ whois friedo.com

(snip)

   Domain Name: FRIEDO.COM
   Registrar: REGISTER.COM, INC.
   Whois Server: whois.register.com
   Referral URL: www.register.com
   Name Server: NS5.1HOURHOSTING.COM
   Name Server: NS6.1HOURHOSTING.COM
   Updated Date: 11-jan-2001

bash-2.02$ whois www.friedo.com

(snip)

   Server Name: WWW.FRIEDO.COM
   **IP Address: 129.21.107.160**
   Registrar: REGISTER.COM, INC.
   Whois Server: whois.register.com
   Referral URL: www.register.com

```

Now it appears some nameservers are getting this info from the WHOIS entry, and some are getting it from the nameserver (like they should.) So, at long last, the question:

How the HELL do I change this entry in the WHOIS database? My domain is registered with [register.com](http://register.com), and I cannot figure it out. (Near as I can tell, this entry shouldn’t even BE in the WHOIS database.)

Thanks for you help.

---

<div class="post-metadata">

**Author:** ![OneChance](https://avatars.discourse-cdn.com/v4/letter/o/74df32/32.png) [@OneChance](https://boards.straightdope.com/u/OneChance)\
**Post date:** [January 31, 2001, 6:50am UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/2 "2001-01-31T06:50:19Z")

</div>

Did you recently change your DNS provider to 1hourhosting from someone else? If so, you should tell your old provider to remove your DNS entries from their tables. Also, you may need to provide more time for propagation of your new information. Anyway, the information you need to change isn’t with the whois database, since that just tells the world where to get your DNS information from.

---

<div class="post-metadata">

**Author:** ![Perderabo](https://avatars.discourse-cdn.com/v4/letter/p/a183cd/32.png) [@Perderabo](https://boards.straightdope.com/u/Perderabo)\
**Post date:** [January 31, 2001, 4:05pm UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/3 "2001-01-31T16:05:23Z")

</div>

First of all, [http://www.friedo.com](http://www.friedo.com) is indeed 64.27.106.52. I just tried nslookup and got that result. My nameserver contacted your namesever to get that ip address.

Then I tried it a second, similiar result, but this time nslookup added “Non-authoritative answer:”. It did that because on the second try my nameserver didn’t bother to contact your nameserver. It cached the previous result. If you now change your ip address again, I won’t see that change immediately. I have to wait until the cached data expires in my nameserver.

You decided how long my nameserver is allowed to cache the data and entered this value on your SOA record. It’s the last number on the record. 86400 seconds is a common choice and that is exactly one day. If that’s your value, then at this time tomorrow I would finally see your new ip address.

---

<div class="post-metadata">

**Author:** ![Joe\_Cool](https://avatars.discourse-cdn.com/v4/letter/j/ecb155/32.png) [@Joe\_Cool](https://boards.straightdope.com/u/Joe_Cool)\
**Post date:** [January 31, 2001, 4:44pm UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/4 "2001-01-31T16:44:18Z")

</div>

I got the right address for you on my linux box, but the old one from my work machine. It usually takes 3 or 4 days for the change to propagate down the mess to every DNS. How long ago did you make the change?

Unfortunately you can’t make that change, the registrar has to do it.

Have you thought about registering your own machine as the nameserver for your domain? It takes a few days for the change to take effect, again, but it’s nice because you can make your own changes without having to depend on anybody else. Of course, before you do that you want to make sure that you have the latest version of BIND and set it not to run as root, so you don’t get hit with the buffer overflow.

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [January 31, 2001, 6:14pm UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/5 "2001-01-31T18:14:23Z")

</div>

Hi folks. Let me clarify that the change was indeed made several weeks ago. I’m aware that it takes a few days for propogation to occur, but this is ludicrous. I’m glad the majority of people can see the correct address, but I still have a few people who can’t. I’m beginning to suspect that their nameservers are simply configured incorrectly and there’s nothing I can do.

As for hosting it on my own machine, I would, but I don’t have a static IP, so I gotta pay someone. ☹

---

<div class="post-metadata">

**Author:** ![OneChance](https://avatars.discourse-cdn.com/v4/letter/o/74df32/32.png) [@OneChance](https://boards.straightdope.com/u/OneChance)\
**Post date:** [January 31, 2001, 7:25pm UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/6 "2001-01-31T19:25:02Z")

</div>

Exactly what changes were made? Did you change your DNS provider, or has 1hourhosting been doing your DNS all along? I assume [Register.com](http://Register.com) did your DNS before, so if that is the case, call them and ask them to remove [friedo.com](http://friedo.com) from their DNS tables. Someone is possibly broadcasting incorrect information for your domain.

---

<div class="post-metadata">

**Author:** ![Bobort](https://avatars.discourse-cdn.com/v4/letter/b/ac8455/32.png) [@Bobort](https://boards.straightdope.com/u/Bobort)\
**Post date:** [February 1, 2001, 2:48am UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/7 "2001-02-01T02:48:08Z")

</div>

Did your old DNS records have a really long TTL? If so, some nameservers could still be caching the old address. In that case, you’ll just have to wait until the TTL expires. The root servers have a 1 day TTL on .com, so there shouldn’t be any cached NS records out there any more for the old address.

It’s possible that some people are using bogus nameservers that don’t respect the TTL, though. Nothing you can do about that.

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [February 1, 2001, 5:13am UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/8 "2001-02-01T05:13:21Z")

</div>

**OneChance** : [Register.com](http://Register.com) was hosting the domain initially (they had it pointed at their default “under construction” page.) I then transferred the domain to 1hour’s DNS server, which seems to be doing everything correctly. Near as I can tell, [register.com](http://register.com) has deleted everything; their nameservers won’t answer authoritatively for [friedo.com](http://friedo.com)

**Bobort** : The TTL was standard (one day I believe.)

---

<div class="post-metadata">

**Author:** ![OneChance](https://avatars.discourse-cdn.com/v4/letter/o/74df32/32.png) [@OneChance](https://boards.straightdope.com/u/OneChance)\
**Post date:** [February 1, 2001, 7:59am UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/9 "2001-02-01T07:59:57Z")

</div>

I have Qwest DSL and the name servers that I use (primary = 206.81.192.1) still see [www.friedo.com](http://www.friedo.com) at 129.21.107.160. I guess all you can do is wait for the cache to clear or hope the name servers needs to be stopped and restarted. It’s also possible, I suppose, that Qwest and other providers that haven’t picked up your new information are querying old root servers. BTW, have you checked the root servers to see if they all have your new information?

---

<div class="post-metadata">

**Author:** ![Perderabo](https://avatars.discourse-cdn.com/v4/letter/p/a183cd/32.png) [@Perderabo](https://boards.straightdope.com/u/Perderabo)\
**Post date:** [February 1, 2001, 2:50pm UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/10 "2001-02-01T14:50:58Z")

</div>

Since the change took place so long ago I would guess that you don’t have a DNS issue at all. Some systems have a hosts file that can override DNS. People use this for various reasons including performance. For example, on our Unix system, we have an entry “hosts: files dns” which tells our resolver to look first at our /etc/hosts file and then if that fails, to use DNS. If I put an entry in our /etc/hosts file of “old.add.re.ss [www.friedo.com](http://www.friedo.com)”, then I will never see the new address. So I would check for that.

If it still looks like DNS, find out their nameserver both hostname and ip address. Then run nslookup using their nameserver and look for [www.freido.com](http://www.freido.com). If you get the right address, it’s not DNS.

---

<div class="post-metadata">

**Author:** ![jrishaw](https://avatars.discourse-cdn.com/v4/letter/j/5fc32e/32.png) [@jrishaw](https://boards.straightdope.com/u/jrishaw)\
**Post date:** [February 1, 2001, 11:26pm UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/11 "2001-02-01T23:26:32Z")

</div>

Fools! 🙂

This is the problem.

**[www.friedo.com](http://www.friedo.com)** is actually a host record registered with [register.com](http://register.com).

**[www.friedo.com](http://www.friedo.com)** must be, or have been, a nameserver for a domain name at some point.

when a certain hostname is listed as a nameserver for a domain, that host record is injected _with IP address_ into the GTLD servers.  
for example, if you register [xyz.com](http://xyz.com) with nameservers [a.xyz.com](http://a.xyz.com) and [b.xyz.com](http://b.xyz.com) - the ip addresses of [a.xyz.com](http://a.xyz.com) and [b.xyz.com](http://b.xyz.com) have to be injected into the GTLD database as name and IP - or otherwise people won’t know how to get to the nameservers (make sense?)

To correct this, you need to delete the host record for [www.friedo.com](http://www.friedo.com) from the [register.com](http://register.com) database.

---

<div class="post-metadata">

**Author:** ![OneChance](https://avatars.discourse-cdn.com/v4/letter/o/74df32/32.png) [@OneChance](https://boards.straightdope.com/u/OneChance)\
**Post date:** [February 2, 2001, 12:41am UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/12 "2001-02-02T00:41:21Z")

</div>

jrishaw, I don’t think that’s right. [www.friedo.com](http://www.friedo.com) may exist as a host record, but that doesn’t mean that everyone still sees it as authoritative for [friedo.com](http://friedo.com). For example, if I change my name servers from ns1/ns2.oldprovider.net to ns1/ns2.newprovider.net, I don’t have to delete the host records for ns1/ns2.oldprovider.net. If what you’re saying is correct, then no one would be able to see [www.freido.com](http://www.freido.com) at its new IP address, but that’s not the case. Anyway, regardless of that, deleting the [www.friedo.com](http://www.friedo.com) host record certainly won’t hurt.

---

<div class="post-metadata">

**Author:** ![jrishaw](https://avatars.discourse-cdn.com/v4/letter/j/5fc32e/32.png) [@jrishaw](https://boards.straightdope.com/u/jrishaw)\
**Post date:** [February 2, 2001, 12:53am UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/13 "2001-02-02T00:53:42Z")

</div>

> [@](#):
>
> \*Originally posted by OneChance \*  
> **If what you’re saying is correct, then no one would be able to see [http://www.freido.com](http://www.freido.com) at its new IP address, but that’s not the case.**
> 
> Right.
> 
> [http://www.friedo.com](http://www.friedo.com) is a glue record in the gtld servers and in [a.root-servers.net](http://a.root-servers.net). If a host query for “[www.friedo.com](http://www.friedo.com) a” goes out to the GTLD servers, it’s going to return the A record of [http://www.friedo.com](http://www.friedo.com) as well as the glue record for [friedo.com](http://friedo.com).
> 
> to illustrate:
> 
> > [@](#):
> >
> > arpa% dig [http://www.friedo.com](http://www.friedo.com) a
> > 
> > ; \<\<\>\> DiG 8.3 \<\<\>\> [http://www.friedo.com](http://www.friedo.com) a  
> > ADDITIONAL: 2  
> > ;; [http://www.friedo.com](http://www.friedo.com), type = A, class = IN
> > 
> > ;; ANSWER SECTION:  
> > [http://www.friedo.com](http://www.friedo.com). 2D IN A 129.21.107.160
> 
> You see here, my first query returned the A record of 129.21.107.160 with a 2-day TTL. 2-day TTL’s are common for records at the GTLD servers or root servers. It’s obvious that the A record of [http://www.friedo.com](http://www.friedo.com) was retrieved from one of the GTLD servers.
> 
> Now, I’ll query the nameserver for [friedo.com](http://friedo.com) directly:
> 
> > [@](#):
> >
> > arpa% dig [http://www.friedo.com](http://www.friedo.com) a @NS5.1HOURHOSTING.com.
> > 
> > ; \<\<\>\> DiG 8.3 \<\<\>\> [http://www.friedo.com](http://www.friedo.com) a @NS5.1HOURHOSTING.com.
> > 
> > ;; ANSWER SECTION:  
> > [http://www.friedo.com](http://www.friedo.com). 1D IN A 64.27.106.52
> 
> See the 1 day TTL? That’s from the ISP.
> 
> Something else that I do find interesting but is not relevant to this problem is that:
> 
> > [@](#):
> >
> > ;; AUTHORITY SECTION:  
> > [friedo.com](http://friedo.com). 1D IN NS [ns5.1hourhosting.com](http://ns5.1hourhosting.com).
> 
> The ISP only has “[ns5.1hourhosting.com](http://ns5.1hourhosting.com)” listed as an authoritative nameserver. It should have both ns5 and ns6.
> 
> I am fairly certain that the problem lies in the host record existing in DNS.
> 
> The original poster should remove that record and see if problems resolve (no pun intended).
> 
> Anyway, regardless of that, deleting the [http://www.friedo.com](http://www.friedo.com) host record certainly won’t hurt.  
> \*\*

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [February 11, 2001, 1:24am UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/14 "2001-02-11T01:24:49Z")

</div>

Thanks, **jrishaw** , that’s some useful information. (I’m perusing the manpage for the dig command too as well.)

However, I’m still confused about changing the A record. Do I do this through [register.com](http://register.com) or my webhost? And you’re right, [www.friedo.com](http://www.friedo.com) at one point doubled as a nameserver.

---

<div class="post-metadata">

**Author:** ![jrishaw](https://avatars.discourse-cdn.com/v4/letter/j/5fc32e/32.png) [@jrishaw](https://boards.straightdope.com/u/jrishaw)\
**Post date:** [February 11, 2001, 1:56am UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/15 "2001-02-11T01:56:54Z")

</div>

> [@](#):
>
> Server Name: [http://www.FRIEDO.COM](http://www.FRIEDO.COM)  
> IP Address: 129.21.107.160  
> Registrar: [REGISTER.COM](http://REGISTER.COM), INC.  
> Whois Server: [whois.register.com](http://whois.register.com)  
> Referral URL: [http://www.register.com](http://www.register.com)

This means that the record for “[www.friedo.com](http://www.friedo.com)” was registered by [http://www.register.com](http://www.register.com).

So, you should contact their support people and simply ask them to remove the “host record” for [http://www.friedo.com](http://www.friedo.com).

Let me know if you have any more questions. Feel free to email me off the board, too, at jamie at arpa dot com (parse it).

Hope this helps.

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [February 11, 2001, 3:28am UTC](https://boards.straightdope.com/t/anyone-know-much-about-dns/52529/16 "2001-02-11T03:28:40Z")

</div>

Thanks. Will do.
