Skip to content
INTERNET INFRASTRUCTURE & NETWORKS

Uncovering the Hidden Traffic Costs of Locally Served Root Zones: Insights from Recent UvA and NLnet Labs Research

The architecture of the Domain Name System (DNS) forms the invisible backbone of the global internet, translating human-readable domain names into machine-routable IP addresses. At the apex of this massive hierarchical structure sits the root zone, the ultimate authority for finding top-level domains (TLDs) like .com, .net, and country-code extensions. Ensuring that root zone queries are handled efficiently, privately, and securely is a continuous challenge for network operators and protocol designers. Recently, researchers have turned their attention toward a specific resolver model known as the locally served root, which pre-fetches and stores a local copy of the root zone directly on the resolver.

In a recent episode of the PING podcast, Willem Toorop from NLnet Labs and Ilyas Rahimi, a recent graduate of the Security and Network Engineering Master’s program at the University of Amsterdam (UvA), sat down to discuss their collaborative research into the real-world effects of deploying locally served root zones. Their empirical investigation sheds light on how different resolver implementations handle root zone retrieval, revealing unexpected network traffic patterns and operational nuances that are becoming increasingly relevant as the Internet Engineering Task Force (IETF) considers formalizing the model as a Best Current Practice.

The research stems from a long-standing academic and professional partnership between NLnet Labs and the University of Amsterdam. NLnet Labs is headquartered on the UvA campus, fostering an environment where open-source infrastructure development intersects closely with academic rigor. Willem Toorop has worked alongside the university’s prominent OS3 Master’s program for many years. The program—named for its core focus on Open Standards, Open Software, and Open Security—requires students to undertake intensive, month-long original research projects. The second of these projects typically serves as the foundation for each student’s Master’s thesis. Under Toorop’s supervision, Rahimi chose to investigate the systemic impacts of locally served root architectures, examining how popular open-source DNS software manages the heavy lifting of maintaining local root copies.

To understand the motivation behind the research, it is essential to examine the mechanics of the locally served root model. Traditionally, recursive resolvers forward queries for data they do not have cached up to the root servers. Under a locally served root configuration, however, the recursive resolver pre-fetches and maintains a local copy of the root zone file. When a client queries the resolver for a non-existent top-level domain—a common occurrence resulting from typos, internal corporate namespace lookups, or malicious scanning—the resolver can immediately terminate the query locally rather than bothering the global root server infrastructure. This local termination not only protects root servers from unnecessary load but also provides tangible privacy benefits for end users by shielding their query patterns from external entities at the top of the DNS hierarchy.

[Podcast] Measuring the impact of locally served root zone | APNIC Blog

Given the operational advantages, the IETF has been actively discussing a proposal to designate locally served root zones as a Best Current Practice (BCP), encouraging wider and more standardized adoption across the global internet. However, moving toward a standardized BCP requires a thorough understanding of the operational trade-offs and side effects associated with the model. To evaluate these dynamics, Rahimi designed a comprehensive testing framework that analyzed three of the industry’s most widely deployed public resolver codebases: BIND, Unbound, and Knot Resolver. His evaluation tested these software packages across four distinct configurations, carefully exploring both in-band retrieval methods of the root zone and out-of-band fetching mechanisms over HTTPS.

The findings from Rahimi’s research challenge some assumptions regarding the network footprint of maintaining local root copies. While locally served roots are designed to minimize traffic directed at global root servers during standard resolution, the process of periodically updating the local root zone itself can generate a surprisingly heavy burden of network traffic. When a resolver fetches the entire root zone during its regular update cycle, the data transfer can be surprisingly substantial. In several of the tested scenarios, Rahimi discovered that the traffic generated by these zone update cycles actually exceeded the traffic associated with the far more frequent, but individually much smaller, queries sent to root servers for uncached data during normal operation.

Furthermore, the research process was not without its unexpected troubleshooting hurdles. During the course of his extensive testing across the different resolver codebases and configurations, Rahimi successfully identified a software bug within the Unbound resolver. This specific bug was responsible for an anomalous spike in network traffic, highlighting the complex edge cases that can emerge when resolvers interact with updated zone management routines. Discoveries of this nature underscore the immense value of rigorous academic research combined with real-world open-source software implementation, as controlled experimentation often brings latent bugs and architectural friction points to the surface before they impact large-scale production networks.

The completion of Rahimi’s thesis marks an important milestone, but both researchers emphasize that there is still significant work remaining in this domain. The OS3 Master’s program at the University of Amsterdam has recently allocated more time within its curriculum for the thesis component, a structural change that will allow future students to dive even deeper into complex networking and security topics. Building on the foundation laid by Rahimi’s project, Willem Toorop hopes to continue the collaborative relationship with UvA students to extend these measurement efforts further. Future research phases are expected to explore alternative update mechanisms, such as investigating how resolver software and the root architecture behave when utilizing incremental zone updates—known as IXFR—rather than downloading the entire root zone file during every single refresh cycle.

As the internet community continues to evaluate proposals for standardizing locally served root zones, empirical studies like the one conducted by Toorop and Rahimi provide essential data for network operators, software developers, and standards organizations. Balancing the privacy and load-reduction benefits of local root deployment against the operational realities of zone update traffic remains a critical engineering challenge. Through ongoing academic partnerships and open-source testing, the broader networking community moves closer to refining these models for resilient, long-term deployment across the global infrastructure.

Leave a Reply

Your email address will not be published. Required fields are marked *