Skip to content

Confusion about what 'authoritative' and 'recursive' DNS do and which you need

Authoritative DNS answers for your zone (you manage vectel.nl). Recursive DNS is the middleman that fetches and caches answers for a client (Google 8.8.8.8, Cloudflare 1.1.1.1, your ISP, your router). You need both, but you manage them separately.

Try this first

  1. 1For your domain you need an authoritative provider (TransIP, Cloudflare, Versio, Route 53). That is where you edit records.
  2. 2For workstation clients you use a recursive resolver. Often the ISP/router default, but 1.1.1.1 or 9.9.9.9 are usually faster and more privacy-friendly.
  3. 3In an office with AD: let clients use the Domain Controllers as recursive (they forward to public resolvers), not 8.8.8.8 directly.
  4. 4Never open a recursive resolver to the public internet. That is an open relay for DNS amplification attacks.
  5. 5When you wonder where a problem lives: dig @authoritative-server versus dig @public-resolver, the difference tells you whether cache or origin is at fault.

When to bring us in

If you have a mix of AD, on-prem resolvers and cloud DNS and records get tangled, we can lay out the architecture again.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.