# DNS and single points of failure

**URL:** <https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337>\
**Category:** Factual Questions\
**Created:** [September 10, 2012, 9:33pm UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337 "2012-09-10T21:33:35Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [September 10, 2012, 9:33pm UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/1 "2012-09-10T21:33:35Z")

</div>

Can someone explain how DNS works? Because this current situation where [GoDaddy.com](http://GoDaddy.com)’s nameservers being down\* causing sites registered with them not to resolve contradicts what I thought I knew about the concept.

DNS servers propagate, right? So why would taking out a couple of them in the chain cause addresses not to resolve? Why wouldn’t redundancy kick in as long as the DNS where the sites are registered is down?

Why create a system with single point of failure like that, especially on the Internet where rerouting around problems is one of its main strengths?

\*Claimed to be by Anonymous, but it’s odd that it’s just one mouthpiece.

---

<div class="post-metadata">

**Author:** ![Noone\_Special](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/noone_special/32/2863_2.png) [@Noone\_Special](https://boards.straightdope.com/u/Noone_Special)\
**Post date:** [September 10, 2012, 9:49pm UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/2 "2012-09-10T21:49:47Z")

</div>

IANA Network engineer, but I am a general-purpose Computer Geek, so the following haphazard handwaving WAG should be in the right direction:

As I understand it, DNS is registered by **domain** , not every last server is propagated all over the 'Net. Each domain has a local DNS server to which all resolution requests (for the domain) get routed, and the multitude of physical and virtual hosts on a domain are resolved _there_ (and cached by your own Name Server.)

So whether a GoDaddy-hosted site is actually in GoDaddy’s domain or has purchased its own, _the physical name server resolving individual servers within the domain_ is – well, _ **was** _ – hosted on GoDaddy. And you can’t reach it now.

Basically, if [widgets.com](http://widgets.com) is hosted on GoDaddy, and you try to ping [bludgeon.widgets.com](http://bludgeon.widgets.com), your local Name Server “knows” where [widgets.com](http://widgets.com)’s Name Server is, and tries to ask it what bludgeon’s IP address is. But the name server itself is located on GoDaddy’s farm, so it’s down… and you may be able to nslookup “[dns.widgets.com](http://dns.widgets.com)”, but not [bludgeon.widgets.com](http://bludgeon.widgets.com) or [hacksaw.widgets.com](http://hacksaw.widgets.com).

I’m sure someone with better knowledge (and a better way with explanations) will be along shortly to correct me.

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [September 10, 2012, 10:00pm UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/3 "2012-09-10T22:00:12Z")

</div>

> [@BigT](#):
>
> Can someone explain how DNS works? Because this current situation where [GoDaddy.com](http://GoDaddy.com)’s nameservers being down\* causing sites registered with them not to resolve contradicts what I thought I knew about the concept.
> 
> DNS servers propagate, right? So why would taking out a couple of them in the chain cause addresses not to resolve? Why wouldn’t redundancy kick in as long as the DNS where the sites are registered is down?

DNS is hierarchical, not peer-to-peer. Every top-level domain has a few bigass nameservers (root nameservers) and the list of these comes in your computer’s Root Zone File which is distributed with every operating system.

The root nameservers hold the addresses of the authoritative name server for every domain registered in that TLD. The root nameservers can tell you the address of the nameserver that has information about the individual domains. _That_ nameserver can then tell you the addresses of individual servers within that domain.

So if a given domain happens to have their DNS hosted on GoDaddy’s DNS servers, then the root nameservers can point you there. But if their DNS servers are broken, then you’re boned.

Now, add to this the fact that DNS servers cache the results of queries for some time. That’s why you can ask your ISP’s DNS server for an address and get a result very fast; your ISP’s DNS server only needs to go to the next level up if the cache timeout for that query has expired. That’s why DNS propagation can take a few hours; you have to wait for everyone’s cache to expire and query the originating nameserver again.

If a DNS server goes down, it’s quite possible that many people would not notice, because their nameservers already have the information cached. But if it stays down for more than a few minutes, more and more people will notice the interruption as their local caches expire.

This situation is exacerbated by the fact that these days, many people deliberately set the expiration time on the DNS records to be very short, for a variety of reasons.

---

<div class="post-metadata">

**Author:** ![Dog80](https://avatars.discourse-cdn.com/v4/letter/d/6bbea6/32.png) [@Dog80](https://boards.straightdope.com/u/Dog80)\
**Post date:** [September 10, 2012, 10:17pm UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/4 "2012-09-10T22:17:15Z")

</div>

I dont know what exactly is wrong with GoDaddy, but some hosting services use the same IP for several websites. If the nameserver is down, knowing and entering the IP into the browser will not give you access to the site because the webserver (assumming it is not down too) won’t know which of the sites sharing that IP you want.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [September 10, 2012, 10:21pm UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/5 "2012-09-10T22:21:49Z")

</div>

> [@friedo](#):
>
> DNS is hierarchical, not peer-to-peer. Every top-level domain has a few bigass nameservers (root nameservers) and the list of these comes in your computer’s Root Zone File which is distributed with every operating system.
> 
> The root nameservers hold the addresses of the authoritative name server for every domain registered in that TLD. The root nameservers can tell you the address of the nameserver that has information about the individual domains. _That_ nameserver can then tell you the addresses of individual servers within that domain.
> 
> So if a given domain happens to have their DNS hosted on GoDaddy’s DNS servers, then the root nameservers can point you there. But if their DNS servers are broken, then you’re boned.
> 
> Now, add to this the fact that DNS servers cache the results of queries for some time. That’s why you can ask your ISP’s DNS server for an address and get a result very fast; your ISP’s DNS server only needs to go to the next level up if the cache timeout for that query has expired. That’s why DNS propagation can take a few hours; you have to wait for everyone’s cache to expire and query the originating nameserver again.
> 
> If a DNS server goes down, it’s quite possible that many people would not notice, because their nameservers already have the information cached. But if it stays down for more than a few minutes, more and more people will notice the interruption as their local caches expire.
> 
> This situation is exacerbated by the fact that these days, many people deliberately set the expiration time on the DNS records to be very short, for a variety of reasons.

So then, I assume the cache isn’t set up to retain the address until explicitly told it’s gone because the assumption is that nameservers often come and go. But, if that’s the case, why do they need to register on GoDaddy’s nameserver at all? Why not just host your own small nameserver that contains your domain name? Sure, you still have to register it to the root nameservers, but then you wouldn’t have to worry about attacks like this. Why put all the registrations in one place, creating a single point of failure?

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [September 10, 2012, 10:23pm UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/6 "2012-09-10T22:23:30Z")

</div>

> [@Dog80](#):
>
> I dont know what exactly is wrong with GoDaddy, but some hosting services use the same IP for several websites. If the nameserver is down, knowing and entering the IP into the browser will not give you access to the site because the webserver (assumming it is not down too) won’t know which of the sites sharing that IP you want.

GoDaddy definitely does this, as the IP to one site I was trying to reach points to a completely different site. How does this work?

Another related question: everyone is talking about how this shows a flaw in GoDaddy’s system. How could it have been set up differently?

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [September 10, 2012, 10:25pm UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/7 "2012-09-10T22:25:34Z")

</div>

> [@BigT](#):
>
> So then, I assume the cache isn’t set up to retain the address until explicitly told it’s gone because the assumption is that nameservers often come and go.

No, the assumption is that data on nameservers changes from time to time, but not often enough that we should contact the authoritative source for every request.

> [@](#):
>
> But, if that’s the case, why do they need to register on GoDaddy’s nameserver at all? Why not just host your own small nameserver that contains your domain name? Sure, you still have to register it to the root nameservers, but then you wouldn’t have to worry about attacks like this. Why put all the registrations in one place, creating a single point of failure?

You could certainly do that. I could also clean my own house. But it’s a lot more convenient to pay some money to the lady who comes every two weeks while I’m at work. Running a DNS, like mopping, is a huge pain in the ass.

---

<div class="post-metadata">

**Author:** ![Number](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/number/32/242_2.png) [@Number](https://boards.straightdope.com/u/Number)\
**Post date:** [September 10, 2012, 10:55pm UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/8 "2012-09-10T22:55:45Z")

</div>

> [@Dog80](#):
>
> I dont know what exactly is wrong with GoDaddy, but some hosting services use the same IP for several websites. If the nameserver is down, knowing and entering the IP into the browser will not give you access to the site because the webserver (assumming it is not down too) won’t know which of the sites sharing that IP you want.

You can, however, add the name and IP to your computer’s [hosts file](http://en.wikipedia.org/wiki/Hosts_(file)) and then browse to it by name.

---

<div class="post-metadata">

**Author:** ![Blakeyrat](https://avatars.discourse-cdn.com/v4/letter/b/ecd19e/32.png) [@Blakeyrat](https://boards.straightdope.com/u/Blakeyrat)\
**Post date:** [September 10, 2012, 11:06pm UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/9 "2012-09-10T23:06:29Z")

</div>

> [@BigT](#):
>
> But, if that’s the case, why do they need to register on GoDaddy’s nameserver at all? Why not just host your own small nameserver that contains your domain name? Sure, you still have to register it to the root nameservers, but then you wouldn’t have to worry about attacks like this. Why put all the registrations in one place, creating a single point of failure?

Anybody can run a DNS server, and it’s done as a matter-of-course of any decent-sized company. If your company has a intranet where you can type “hr” to get to the internal human resources site, for example, your company runs its own DNS servers. It requires some specialized knowledge, though.

A factor here is that a lot of people running web servers, even for popular sites, don’t really understand how DNS works. Another factor is that 0.001% of the time that GoDaddy’s (or whoever’s) DNS is down isn’t worth the effort of maintaining your own DNS server 100% of the time.

---

<div class="post-metadata">

**Author:** ![sco3tt](https://avatars.discourse-cdn.com/v4/letter/s/45deac/32.png) [@sco3tt](https://boards.straightdope.com/u/sco3tt)\
**Post date:** [September 11, 2012, 4:00am UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/10 "2012-09-11T04:00:15Z")

</div>

> [@BigT](#):
>
> GoDaddy definitely does this, as the IP to one site I was trying to reach points to a completely different site. How does this work?

[Virtual hosting](http://en.wikipedia.org/wiki/Virtual_hosting#Name-based).

Basically, your hosting provider serves multiple sites/domains that all resolve to the same IP address. When you access any of those sites your browser resolves the IP address via DNS, then issues an HTTP request to that address, sending along the server and domain name itself in one of the HTTP headers. The webserver parses that header value to figure out which of the multiple sites at that IP you are trying to reach and responds with the appropriate content.

This is why a lot of sites can’t be accessed via IP address alone anymore, and why old pre-HTTP/1.1 browsers from before 1996 won’t get very far on the web today. Without that Host header, the server won’t know which site to serve the request from.

---

<div class="post-metadata">

**Author:** ![Dog80](https://avatars.discourse-cdn.com/v4/letter/d/6bbea6/32.png) [@Dog80](https://boards.straightdope.com/u/Dog80)\
**Post date:** [September 11, 2012, 4:26am UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/11 "2012-09-11T04:26:15Z")

</div>

> [@Number](#):
>
> You can, however, add the name and IP to your computer’s [hosts file](http://en.wikipedia.org/wiki/Hosts_(file)) and then browse to it by name.

No, it will still not work unless the site you are looking for has a dedicated IP. Read **sco3tt** ’s explanation.

For example, my website’s IP is 46.4.61.68. [Enter that IP here](http://www.yougetsignal.com/tools/web-sites-on-web-server/) and see how many websites are under the same IP.

---

<div class="post-metadata">

**Author:** ![Number](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/number/32/242_2.png) [@Number](https://boards.straightdope.com/u/Number)\
**Post date:** [September 11, 2012, 4:34am UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/12 "2012-09-11T04:34:41Z")

</div>

Your browser doesn’t care if the name is resolved through DNS or the hosts file. Either way it sends the name in the HTTP headers, so the server knows exactly what site to serve. As long as the IP and the name are valid, it will work fine.

---

<div class="post-metadata">

**Author:** ![Dog80](https://avatars.discourse-cdn.com/v4/letter/d/6bbea6/32.png) [@Dog80](https://boards.straightdope.com/u/Dog80)\
**Post date:** [September 11, 2012, 4:46am UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/13 "2012-09-11T04:46:26Z")

</div>

> [@Number](#):
>
> Your browser doesn’t care if the name is resolved through DNS or the hosts file. Either way it sends the name in the HTTP headers, so the server knows exactly what site to serve. As long as the IP and the name are valid, it will work fine.

Duh, of course you’re right all along. Ignorance fought 🙂

---

<div class="post-metadata">

**Author:** ![Number](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/number/32/242_2.png) [@Number](https://boards.straightdope.com/u/Number)\
**Post date:** [September 11, 2012, 5:05am UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/14 "2012-09-11T05:05:02Z")

</div>

It is easy to get the concepts mixed up. I probably should have added more of an explanation in my first reply.

I’ve been writing iRules for F5 load balancers for the last three weeks straight, so the subject is somewhat fresh in my head.

---

<div class="post-metadata">

**Author:** ![FoundWaldo](https://avatars.discourse-cdn.com/v4/letter/f/dfb087/32.png) [@FoundWaldo](https://boards.straightdope.com/u/FoundWaldo)\
**Post date:** [September 11, 2012, 5:30am UTC](https://boards.straightdope.com/t/dns-and-single-points-of-failure/634337/15 "2012-09-11T05:30:10Z")

</div>

> [@Blakeyrat](#):
>
> Anybody can run a DNS server, and it’s done as a matter-of-course of any decent-sized company. If your company has a intranet where you can type “hr” to get to the internal human resources site, for example, your company runs its own DNS servers. It requires some specialized knowledge, though.
> 
> A factor here is that a lot of people running web servers, even for popular sites, don’t really understand how DNS works. Another factor is that 0.001% of the time that GoDaddy’s (or whoever’s) DNS is down isn’t worth the effort of maintaining your own DNS server 100% of the time.

Even many large, clueful sites don’t run their own DNS. Companies like UltraDNS and Akamai run DNS for huge parts of the Internet. These providers have points of presence on every continent, using anycast and other techniques to provide much more redundancy and performance than you could ever hope to get out of a couple of DNS servers running in your company’s data center (or more likely colo, or on a cloud server somewhere).

IMHO, really there are only two categories of people who should be running their own _external_ DNS (internal is a different matter):

1. Geeky folks who enjoy tinkering with this kind of stuff (or want to learn about it) and are running non-critical personal sites.
2. Massive, top-tier companies with global infrastructure and deep technology expertise (think Google, Amazon, etc.).

Everyone else should let someone else host their DNS. On the low end, use your web/mail hosting provider, on the medium-end use something like Amazon’s Route53 or DNS Made Easy (those can both scale beyond medium-end, but unlike many of the other big players, they’re affordable for smaller scale operations). On the higher end, you can also consider Akamai, UltraDNS, etc. Here’s an interesting article comparing some of the players: [http://blog.cloudharmony.com/2012/08/comparison-and-analysis-of-managed-dns.html](http://blog.cloudharmony.com/2012/08/comparison-and-analysis-of-managed-dns.html). It has some pricing info near the end, to give you a sense of what we’re talking about here.
