Skip to content
Skip to main content
IP Addresses & Networks Technical Explainer

What is the difference between a DNS resolver and an authoritative DNS server?

A DNS resolver and an authoritative DNS server both take part in DNS, but they do different jobs.

Resolver: finds the answer

A resolver is the service a device asks to find DNS information on its behalf. It may be run by an internet provider, workplace, mobile network or public DNS service.

When it receives a query, it:

  1. checks whether it already has a valid cached answer;
  2. follows the DNS hierarchy if it needs to find the answer; and
  3. returns the result to the device.

It is often called a recursive resolver because it does the searching on the device's behalf.

Authoritative server: publishes the answer

An authoritative server publishes the DNS records for a domain or DNS zone. It answers from the records it is responsible for rather than searching the wider DNS system for the device.

It may be operated by:

  • the organisation controlling the domain;
  • a DNS-hosting company;
  • a cloud platform; or
  • a content-delivery network.

One question, two observation points

Dave's laptop asks a workplace resolver for portal.example. The workplace resolver has no cached answer, so it asks the relevant authoritative service. The systems can record different clients even though the entries relate to the same lookup.

Why the difference matters to an investigator

The two systems see the lookup from different positions.

System holding the log What it may see
Device or local resolver The application, device or private address making the request
Provider or public resolver The public connection or another resolver forwarding the request
Authoritative server Usually the resolver asking for the record, not the original device

If a resolver answers from cache, the authoritative server may see no new query at all.

A worked comparison might look like this:

Record holder Apparent client Name Evidential meaning
Workplace resolver 10.20.5.14 portal.example A client at that private address asked the workplace resolver
Authoritative DNS provider 198.51.100.53 portal.example The workplace resolver asked the authoritative service

The second row does not identify Dave's laptop. The useful relationship is that the resolver's outward query may explain how it obtained the answer later supplied to the internal client.

Before interpreting a DNS query log, identify which system created it. That tells you whether the apparent client is likely to be a device, a local network, a public connection or simply another DNS server.

Operational takeaway

Identify the record holder before interpreting the client field. A resolver log may be close to the requesting device; an authoritative-server log usually sees the resolver, not the original user or device.

Explore related guidance
Reference: IP-037IP Addresses & Networks