What is the difference between a DNS resolver and an authoritative DNS server?¶
A DNS resolver and an authoritative DNS server both take part in DNS, but they do different jobs.
Resolver: finds the answer¶
A resolver is the service a device asks to find DNS information on its behalf. It may be run by an internet provider, workplace, mobile network or public DNS service.
When it receives a query, it:
- checks whether it already has a valid cached answer;
- follows the DNS hierarchy if it needs to find the answer; and
- returns the result to the device.
It is often called a recursive resolver because it does the searching on the device's behalf.
Authoritative server: publishes the answer¶
An authoritative server publishes the DNS records for a domain or DNS zone. It answers from the records it is responsible for rather than searching the wider DNS system for the device.
It may be operated by:
- the organisation controlling the domain;
- a DNS-hosting company;
- a cloud platform; or
- a content-delivery network.
One question, two observation points¶
Dave's laptop asks a workplace resolver for portal.example. The workplace resolver has no cached answer, so it asks the relevant authoritative service. The systems can record different clients even though the entries relate to the same lookup.
Why the difference matters to an investigator¶
The two systems see the lookup from different positions.
| System holding the log | What it may see |
|---|---|
| Device or local resolver | The application, device or private address making the request |
| Provider or public resolver | The public connection or another resolver forwarding the request |
| Authoritative server | Usually the resolver asking for the record, not the original device |
If a resolver answers from cache, the authoritative server may see no new query at all.
A worked comparison might look like this:
| Record holder | Apparent client | Name | Evidential meaning |
|---|---|---|---|
| Workplace resolver | 10.20.5.14 | portal.example | A client at that private address asked the workplace resolver |
| Authoritative DNS provider | 198.51.100.53 | portal.example | The workplace resolver asked the authoritative service |
The second row does not identify Dave's laptop. The useful relationship is that the resolver's outward query may explain how it obtained the answer later supplied to the internal client.
Before interpreting a DNS query log, identify which system created it. That tells you whether the apparent client is likely to be a device, a local network, a public connection or simply another DNS server.
Operational takeaway
Identify the record holder before interpreting the client field. A resolver log may be close to the requesting device; an authoritative-server log usually sees the resolver, not the original user or device.