In the latest episode of the PING podcast, the intersection of academic research and foundational internet infrastructure takes center stage as host and guests dive deep into the mechanics of the Domain Name System (DNS). The episode features Willem Toorop from NLnet Labs and Ilyas Rahimi, a recent graduate of the prestigious Master’s in Security and Network Engineering program at the University of Amsterdam (UvA). Together, they unpack their recent, rigorous investigation into the operational impacts of locally served root zones, shedding light on unexpected network behaviors that challenge prevailing assumptions about local DNS optimization.
The collaborative discussion bridges the gap between theoretical computer science and practical network engineering. Ilyas completed his studies in UvA’s renowned OS3 Master’s program—an acronym reflecting its core educational pillars of Open Standards, Open Software, and Open Security. Located directly on the UvA campus, NLnet Labs has maintained a long-standing, fruitful partnership with the academic institution. For many years, Willem Toorop has worked closely with the program, stepping in as a supervisor for student research initiatives focusing on critical internet protocols such as DNS and DNSSEC during the thesis phase of the curriculum.
Within the framework of the OS3 Master’s program, students are required to undertake a pair of intensive, month-long original research projects. The second of these projects serves as the foundational cornerstone for their master’s thesis, demanding a high level of empirical rigor, technical depth, and practical experimentation. It was through this demanding academic structure that Ilyas embarked on his deep dive into locally served root zones, examining how they behave in real-world deployment scenarios and what unintended consequences they might introduce to wider network infrastructures.
To understand the gravity of the research, it is essential to examine the concept of the locally served root zone itself. At the apex of the global DNS hierarchy sits the root zone, the ultimate authority that directs queries for top-level domains like .com, .org, or country-code extensions. Traditionally, recursive resolvers must query root servers across the global internet to resolve names that fall outside their local cache. A locally served root resolver model changes this paradigm by pre-fetching and locally storing a copy of the root zone directly within the recursive resolver.
Maintaining this local copy yields several distinct theoretical advantages. Most notably, it allows resolvers to swiftly and authoritatively terminate queries for non-existent top-level domains right at the edge, preventing unnecessary external lookup traffic. Furthermore, it offers meaningful privacy benefits by minimizing the exposure of client query patterns to external root servers, since the resolver no longer needs to query the global root infrastructure for resolvable names that can be mapped locally. Recognizing these potential efficiencies, the Internet Engineering Task Force (IETF) has seen a formal proposal aimed at establishing locally served root zones as a Best Current Practice (BCP) across the global operator community.
However, moving from theory to implementation requires rigorous testing, which formed the core of Ilyas’s research project. He evaluated three widely deployed public resolver codebases—BIND, Unbound, and Knot Resolver—across four distinct operational configurations. His methodology was designed to stress-test the mechanisms used to acquire the root zone, exploring both in-band retrieval methodologies and fetching the root zone securely over HTTPS. By systematically observing how these different codebases handled the routine updates required to keep a local root zone current, the research team uncovered unexpected operational realities.
![[Podcast] Measuring the impact of locally served root zone | APNIC Blog](https://blog.apnic.net/wp-content/uploads/2026/09/ChatGPT-Image-Sep-1-2026-10_39_26-AM.png)
One of the most striking findings from the empirical research was the discovery of a specific bug within the Unbound resolver codebase. This software defect was directly responsible for accounting for a notable spike in network traffic during update cycles. More broadly, however, the research revealed that the very process of updating the local root zone can generate a surprisingly large volume of network traffic when fetching the zone data. In several observed scenarios, the bandwidth and packet volume consumed by the root zone update cycle actually exceeded the traffic associated with standard, uncached queries sent to root servers—despite those individual queries occurring far more frequently, albeit carrying much smaller payloads.
This revelation complicates the narrative surrounding local root serving. While the model successfully reduces external exposure and accelerates certain negative responses, the heavy lifting involved in periodically downloading and synchronizing the full root zone can introduce substantial traffic bursts on the network. These findings provide critical data for network operators and standards bodies as they weigh the broader deployment of locally served root zones and consider whether the IETF draft should be formally codified as a Best Current Practice.
The collaboration between UvA and NLnet Labs is far from concluded, as these initial findings have opened the door to several compelling avenues for future investigation. With the OS3 Master’s thesis component recently allocated more expanded time within the formal degree program, Willem Toorop expresses optimism about continuing the partnership with future cohorts of UvA students. This extended timeline will enable researchers to broaden the scope of their measurement work and dig deeper into the nuances of resolver behavior.
Already, discussions and preliminary tests are underway to examine how the system behaves under alternative update mechanisms. Specifically, researchers are exploring the implementation of incremental zone updates—utilizing IXFR (Incremental Zone Transfer) rather than downloading the entire, monolithic root zone file each time an update is triggered. By shifting from full zone transfers to incremental changes, it may be possible to mitigate the traffic spikes observed during Ilyas’s research, balancing the operational benefits of local root serving with a more efficient use of network resources.
The insights shared in this episode underscore the dynamic and constantly evolving nature of core internet protocols. As the technical community continues to refine how the DNS operates at scale, empirical research conducted by students and open-source laboratories plays an indispensable role in identifying hidden friction points, rectifying software bugs, and ensuring that proposed standards truly deliver on their intended operational promises. Listeners interested in a comprehensive breakdown of the methodology, the specific codebases tested, and the complete set of empirical results can explore the published research paper linked through the PING podcast channel.
Leave a Reply