Skip to content
INTERNET INFRASTRUCTURE & NETWORKS

Adding a Second Nameserver Dramatically Reduces DNS Query Repetition, New APNIC Study Finds

Recent research into the puzzling behavior of the Domain Name System (DNS) has uncovered an unexpected operational quirk: adding a second authoritative nameserver to a domain significantly reduces the volume of redundant and repeat queries sent by recursive resolvers.

The findings serve as a follow-up to a broader APNIC measurement study conducted earlier this autumn, which originally investigated the surprisingly large number of repeat queries circulating through the global DNS infrastructure. That initial research, titled "What part of ‘No!’ is so hard for the DNS to understand?", examined a scenario where millions of users were tasked with resolving a completely unique DNS name specifically designed to bypass conventional DNS caching mechanisms.

When the initial testing window ran from August 5 to August 11, researchers recorded millions of test iterations across various response types. In scenarios featuring definitive negative responses—such as NXDOMAIN and NODATA—or standard positive responses, a relatively stable query profile emerged. On average, those tests involved roughly four queries total. Approximately 55% to 60% of those tests completed smoothly with a single query, and when query repetition did occur, resolvers typically issued an additional four to six repeat queries.

However, the baseline behavior shifted dramatically when the DNS encountered non-definitive or error-laden responses. While a REFUSED response still completed with a single query about 40% of the time, it triggered an average of 11 further repeat queries in other cases. More extreme patterns materialized during SERVFAIL and NO RESPONSE scenarios, where recursive resolvers repeatedly hammered the authoritative nameserver with tens of millions of redundant requests, averaging over 80 queries per test.

One or two nameservers? | APNIC Blog

Crucially, those baseline measurements were executed using a solitary authoritative nameserver for each designated measurement zone. The researchers’ global measurement framework divides the internet into six distinct operational zones: North America, South America, Europe and Africa, India, Asia, and China. Within each of those zones, the setup deliberately relied on a single authoritative nameserver configured as a dual-stack system possessing both an IPv4 and an IPv6 address.

Faced with those initial findings, a natural question arose among network operators and researchers: would the system experience more or fewer repeat queries if a given zone were backed by multiple dual-stack nameservers rather than just one? Conventional networking wisdom might lead an engineer to expect a higher cumulative count of repeat queries when introducing more authoritative servers. The assumption is that an obsessive or overly cautious recursive resolver would systematically query every available authoritative nameserver for the exact same record to ensure that all responding nodes are operating in a mutually consistent manner.

To test this hypothesis, the researchers repeated the control measurement using two authoritative dual-stack nameservers instead of one. The resulting data defied standard expectations entirely.

When the zone was served by a single nameserver, roughly 58% of the test cases successfully completed the experiment using a single DNS query for each query type. When a second nameserver was introduced, that single query completion rate jumped to 71%. Simultaneously, the average number of overall queries per test dropped significantly from 3.43 down to 2.57. Furthermore, in instances where a query was repeated, the average number of repeat queries fell from 3.8 down to 2.6.

One or two nameservers? | APNIC Blog

This counterintuitive reduction in query duplication highlights a fascinating aspect of modern DNS resolution mechanics. While the DNS handles individual requests relatively opaquely, leaving researchers unable to pinpoint every underlying software trigger, the temporal distribution of these repeat queries offers vital clues about their origin.

Analyzing the cumulative distribution of repeat queries over time reveals that the most prominent behavioral divergence occurs during the very first second of DNS name resolution. In the single-nameserver setup, slightly more than 85% of all duplicate queries arrived within that initial one-second window. By contrast, that figure dropped to 75% when two nameservers were present. Moreover, the two-nameserver configuration exhibited characteristics resembling an exponential backoff pattern, showing minor secondary peaks in repeat queries at roughly 0.75 seconds, 1.5 seconds, and 3 seconds. Across both configurations, roughly 90% of all repeated queries were observed within the first five seconds of the test.

A granular look at the sub-second distribution of these repeat queries uncovers even sharper operational contrasts. When operating with a single nameserver, 17% of all repeated queries materialized within a mere 10 milliseconds of the initial query—a phenomenon characterized as "rapid-fire" query duplication. When a second nameserver was added, that rapid-fire duplication rate dropped to 12%. Furthermore, the single-nameserver environment displayed distinct local peaks of duplicate queries at 100 milliseconds, 310 milliseconds, and 800 milliseconds. The two-nameserver environment, meanwhile, produced a more fragmented distribution with peaks appearing at 50, 100, 310, 370, 750, and 800 milliseconds.

To determine whether this behavior stems from individual recursive resolver implementations acting erratically or from structural changes within massive resolver architectures, researchers examined the query repetition patterns originating from individual resolver IP addresses.

One or two nameservers? | APNIC Blog

The normalized comparison between the datasets pointed directly to a critical time interval between 10ms and 70ms post-query, during which the single-server setup sustained a notably higher volume of repeat traffic, particularly in the 10ms-to-40ms bracket. Because this specific timeframe sits well below the standard User Datagram Protocol (UDP) timeout thresholds typically configured in individual resolver software, the rapid repetition points away from standard timeout retries and toward architectural design choices.

The most plausible explanation for this behavior points to the deployment of modern resolver "farms." Large consumer Internet Service Providers and major public DNS providers routinely handle traffic volumes that far exceed the capacity of a single standalone platform. To manage this scale, network operators commonly place a front-end query dispatcher in front of a cluster of individual recursive resolver engines.

Systems such as PowerDNS’s DNSdist are frequently deployed in this fashion, utilizing a relay-like mechanism where a public-facing IP address absorbs incoming traffic from the internet while utilizing private internal IP addresses to route work among backend resolver engines. Within such an infrastructure, front-end dispatchers may be programmed to aggressively duplicate incoming queries across multiple internal resolver instances if they detect only a single authoritative nameserver, attempting to optimize resolution speed and service resilience in the absence of broader server redundancy.

While the exact internal logic of these proprietary resolver farms remains opaque to external observers, the empirical evidence strongly reinforces long-standing operational guidelines. The findings demonstrate clear practical value in the enduring operational advice that domain administrators should always configure a minimum of two nameservers to serve a zone. Providing multiple authoritative endpoints not only satisfies core DNS resilience standards, but also appears to pacify the aggressive duplication tendencies of modern recursive resolver infrastructure.

Leave a Reply

Your email address will not be published. Required fields are marked *