name server
A server that stores DNS record One entry in a DNS zone, made of a name, a type, a TTL and data. Full definition of DNS record and answers questions about domain name A readable internet name made of labels separated by dots. Full definition of domain name. For a domain to work, the registrar A company that registers domain names for customers with the registry. Full definition of registrar tells the registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry which name servers hold its records. Changing a domain's name servers changes where its website and email are found.
- category
- DNS and technical foundations
A name server is the computer that answers when someone asks where a domain’s website or email can be found. Every domain is required to have at least two, and the registrar lists them at the registry. If they are missing, wrong or switched off, the domain stops working, even though it is still registered.
What a name server does for your domain
The words “name server” and “DNS server” cover two jobs. authoritative server A DNS server that gives the official answers for a domain or zone. Full definition of authoritative server hold a domain’s DNS records and answer for it; resolver The DNS server that looks up domain names on behalf of users. Full definition of resolver ask those questions on behalf of users. RFC Request for Comments A numbered document in the series recording the internet's technical standards and practices. Full definition of RFC 9499 (March 2024), the DNS Domain Name System The internet's directory that links domain names to computer addresses. Full definition of DNS terminology document, notes that both are often called name servers. Here the term means the authoritative ones.
The zone above the domain, held by the registry of its TLD top-level domain The last part of a domain name, after the final dot. Full definition of TLD, contains NS record Name Server record A DNS record that lists the name servers responsible for a domain. Full definition of NS record naming the domain’s servers. This delegation tells resolvers where to ask. The registrar sends those names to the registry through EPP Extensible Provisioning Protocol The protocol registrars use to manage domain names at registries. Full definition of EPP. A domain with no name servers has the status inactive Status code for a registered domain with no name servers, so it does not resolve. Full definition of inactive and does not resolve.
RFC 1034 (November 1987) requires every zone to be on at least two servers, so that it survives the failure of one. The SSAC Security and Stability Advisory Committee ICANN's expert committee on security and stability of naming and addressing. Full definition of SSAC report SAC125 (9 May 2024) notes that registries typically require at least two at registration Obtaining the right to use a domain name for a set period. Full definition of registration and on every update.
Registrar, DNS provider and host: who runs your name servers
Three roles are involved, filled by one company or by three:
- The registrar records at the registry which name servers the domain uses.
- The DNS provider A company that runs the name servers for a domain, which may differ from the registrar. Full definition of DNS provider runs those servers and the zone with the domain’s records. It can be the registrar, a web host or a specialist.
- Web and email hosts run the services the records point to.
Changing DNS provider does not change the registrar: only the name servers listed for the domain are replaced.
How to change name servers, step by step
- Set up the zone at the new DNS provider first, with every record the domain uses, including website and email, and NS records matching the new name servers.
- If the domain is signed with DNSSEC Domain Name System Security Extensions Digital signatures that prove DNS answers are genuine and unchanged. Full definition of DNSSEC, a DS record Delegation Signer A record in the parent zone that links a domain's DNSSEC key to the chain of trust. Full definition of DS record left pointing to the old keys can make it fail for resolvers that check signatures. Where the old operator does not cooperate, RFC 6781 describes this order: ask for the DS record to be removed, change the name servers, wait until the change has spread through the DNS, then add a DS record for the newly signed zone. The domain is not protected by DNSSEC until then.
- Check that the domain is not locked against updates: while clientUpdateProhibited Registrar-set status code that blocks changes to the domain's data. Full definition of clientUpdateProhibited or serverUpdateProhibited Registry-set status code that blocks changes to the domain's data. Full definition of serverUpdateProhibited is set, the registry rejects changes. The registrar lifts clientUpdateProhibited; serverUpdateProhibited (registry lock A registry-level lock that strongly protects a domain against unauthorized changes. Full definition of registry lock) can only be removed by the registry, through the registrar.
- Enter the new name servers at the registrar, which passes them to the registry. List at least two, ideally on separate networks.
- Keep the old service running for a while: resolvers keep copies of answers, so some visitors reach the old servers for hours or longer. Do not delete the old zone on the same day.
Rules, locks and timing depend on the registry and registrar, so check with them before changing a domain that matters.
Glue records and name servers inside your own domain
Take example.com, with name servers ns1.example.com and ns2.example.com. To find ns1.example.com, a resolver would first have to ask the name servers of example.com: the very servers it is looking for. The way out is the glue record An address record held at the registry for a name server inside the domain it serves. Full definition of glue record: the registry publishes the IP Internet Protocol The internet's basic rules for sending data, using numeric addresses for every connected device. Full definition of IP of those servers with the delegation. RFC 9471 (September 2023) makes this glue mandatory in referral answers, and noted then that addresses (A and AAAA record A DNS record that points a domain name to an IPv6 address. Full definition of AAAA record) were the only kind of glue defined.
At the registry, each name server is a host object The registry's record of a name server that domains can be linked to. Full definition of host object. Because ns1.example.com sits under example.com, the domain must exist first; the registrar then creates the host object with its IP addresses and links the domain to it. Addresses are required only when glue is needed: if example.com used ns1.example.net, the .com registry would need no glue for it.
Primary and secondary servers, and why redundancy matters
The primary server holds the copy of the zone where changes are made. Secondary servers copy it by zone transfer Copying a DNS zone from one name server to another, in full or in part. Full definition of zone transfer: a full transfer (AXFR) copies the whole zone, an incremental one (IXFR) only what has changed. The dynamic DNS Automatic updating of DNS records, often for connections whose IP address changes. Full definition of dynamic DNS protocol (RFC 2136), the standard part of dynamic DNS, adds or deletes records without editing the zone by hand.
Two servers are the minimum, not the advice: RFC 2182 (July 1997) warns that a zone with only two “is actually running with just one” once one fails, and recommends three for most organisations, with at least one well removed from the others, and four or five for higher reliability.
IANA Internet Assigned Numbers Authority The functions that coordinate the root zone, IP addresses and protocol numbers. Full definition of IANA’s technical requirements (last revised on 14 November 2024, as of October 2026) apply only to the root zone The top of the DNS, listing every TLD and its name servers. Full definition of root zone, .INT and .ARPA, but make a useful checklist: at least two NS records on different IP addresses, servers in at least two topologically separate networks, authoritative answers and no recursive service.
What goes wrong: lame delegations and forgotten servers
“lame delegation A delegation pointing to a name server that does not answer for the domain. Full definition of lame delegation” is used for several faults: a listed server that does not answer, cannot be reached, or answers with an error or without authority. RFC 9499 recommends more specific wording. Either way, lookups slow down or fail. A common cause is a forgotten server: a registrant The person or organization that holds a domain name registration. Full definition of registrant leaves a DNS provider without changing the NS records, and the domain stays delegated to servers that no longer answer for it, which can open the way to a takeover.
A less visible risk: according to SAC125, most registries refuse to delete an expired domain while other domains depend on it, and RFC 5731 says it should not be deleted until its host objects are deleted or renamed. Some registrars have renamed them into another domain. SAC125 calls these sacrificial name servers, unsafe when that other domain can be registered: whoever registers it controls resolution of every domain still using them. As of September 2020, it reports, this had exposed over 500,000 gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD domains to hijacking risk, and the resolution of over 163,000 had fallen under unauthorized control; SAC125 notes that the extent in ccTLD country code top-level domain A top-level domain for a country or territory, usually two letters long. Full definition of ccTLD is unknown. It recommends a code of conduct for registries and registrars; as of October 2026 no adopted code had been confirmed.
Renewing the domains that host your name servers reduces this risk.
Sources
- RFC 9499: DNS Terminology, opens another website in a new tab
- RFC 2182: Selection and Operation of Secondary DNS Servers, opens another website in a new tab
- RFC 6781: DNSSEC Operational Practices, Version 2, opens another website in a new tab
- Technical requirements for authoritative name servers (IANA), opens another website in a new tab
- SAC125: SSAC Report on Registrar Nameserver Management, opens another website in a new tab