root zone

The top level of the DNS Domain Name System The internet's directory that links domain names to computer addresses. Full definition of DNS. It lists every TLD top-level domain The last part of a domain name, after the final dot. Full definition of TLD, such as .com or .es, and the name server A server that holds a domain's DNS records and answers lookups. Full definition of name server for each one. Adding a new gTLD A generic top-level domain added to the internet through ICANN's New gTLD Program. Full definition of new gTLD to the internet means adding it to the root zone, a process coordinated through IANA Internet Assigned Numbers Authority The functions that coordinate the root zone, IP addresses and protocol numbers. Full definition of IANA.

category
DNS and technical foundations

Updated on 4 min read

The root zone is the top of the Domain Name System: a small, public list of every top-level domain (TLD), such as .com or .es, and of the servers that answer for each one. When a resolver The DNS server that looks up domain names on behalf of users. Full definition of resolver does not know where to find a TLD, it asks a root server A server that answers for the DNS root zone and points to TLD servers. Full definition of root server, which answers from the root zone. A TLD only works on the internet once it is listed there.

What the root zone is and what it contains

IANA describes the root zone as “principally composed of delegations of top-level domains”. For each TLD it holds the name servers, as NS record Name Server record A DNS record that lists the name servers responsible for a domain. Full definition of NS record, and the DS record Delegation Signer A record in the parent zone that links a domain's DNSSEC key to the chain of trust. Full definition of DS record that link the TLD into the chain of trust The linked DNSSEC signatures from the root zone down to a domain. Full definition of chain of trust. It also carries the addresses of the root servers themselves. It holds no individual domains such as example.com: it only points to each TLD’s servers.

Anyone can download the complete root zone file from IANA, with the same data the root servers serve. IANA also keeps the Root Zone Database, which records each TLD’s manager, technical details and contacts. The root zone has been signed with DNSSEC Domain Name System Security Extensions Digital signatures that prove DNS answers are genuine and unchanged. Full definition of DNSSEC since July 2010.

Root servers: how many there are and who runs them

The root zone is served by 13 named identities, a.root-servers.net to m.root-servers.net. That number counts names and addresses, not machines: IANA describes “a network of hundreds of servers in many countries”. As of 9 October 2026, root-servers.org counted 2,047 operational instances run by 12 independent organizations; Verisign The company that operates the .com and .net registries. Full definition of Verisign runs two identities, a and j.

Under a 2019 RSSAC Root Server System Advisory Committee ICANN's advisory committee on the root server system. Full definition of RSSAC statement, operators must stay independent of each other and of any government or overarching organization, and they work under different legal jurisdictions.

How a TLD is added to or removed from the root

Adding a TLD is called delegation, a separate step from applying for it. For a new gTLD, it comes after ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN signs a Registry Agreement The contract between ICANN and a gTLD registry operator. Full definition of Registry Agreement and runs pre-delegation testing. The registry operator The organization that holds the contract or mandate for a TLD and sets its rules. Full definition of registry operator then submits its manager, contacts, name servers and DS records through IANA’s Root Zone Management system, and its NS records are placed in the root zone.

Every root zone change, including new name servers for an existing TLD, goes through IANA’s reviews and technical tests and must be confirmed by the TLD’s contacts before it is implemented. A substantial change of control is treated as a redelegation, with its own criteria.

A ccTLD country code top-level domain A top-level domain for a country or territory, usually two letters long. Full definition of ccTLD exists because its country or territory has a code in ISO 3166-1 The standard list of country codes that decides which ccTLDs can exist. Full definition of ISO 3166-1. When the code is removed, IANA issues a Notice of Removal. As of October 2026, the ccTLD goes after five years by default, or at most 10 if an extension is requested within 12 months of the notice. The ICANN Board ICANN's board of directors, which adopts policies and approves key decisions. Full definition of ICANN Board adopted this policy on 22 September 2022.

A gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD whose Registry Agreement is terminated, and which ICANN does not move to a successor registry operator, has its delegation revoked; the string may be offered again in a future application round.

Who controls changes: IANA, the maintainer and the operators

  • IANA, whose functions are performed by PTI Public Technical Identifiers The ICANN affiliate that performs the IANA functions, including root zone changes. Full definition of PTI, an ICANN affiliate, checks each change request and keeps the Root Zone Database. Changes start with the TLD manager, who submits them online and must confirm them.
  • Verisign, as Root Zone Maintainer The organization that produces and distributes the root zone file, currently Verisign. Full definition of Root Zone Maintainer under an agreement with ICANN, compiles the zone at IANA’s direction, signs it with the zone signing Adding DNSSEC signatures to all the records in a DNS zone. Full definition of zone signing key and sends it to the operators. As of October 2026, the agreement (signed on 28 September 2016, amended on 20 October 2024) runs for eight-year terms that renew automatically.
  • The root server operator One of the twelve organizations that run the DNS root servers. Full definition of root server operator serve the zone exactly as distributed. RSSAC001 (December 2015) notes that an operator could not alter the signed data without invalidating its signatures.

Myths about “turning off the internet” at the root

  • There is no single switch. Twelve independent operators in different jurisdictions run more than 2,000 instances.
  • Operators cannot quietly edit entries. RRSIG Resource Record Signature The DNS record that carries a DNSSEC signature for a set of records. Full definition of RRSIG would expose a change.
  • A short outage barely shows. According to RFC Request for Comments A numbered document in the series recording the internet's technical standards and practices. Full definition of RFC 8806, resolvers usually keep TLD data cached for “on the order of a day or two”.

That does not make the root immune. On 23 December 2025, a DDoS attack distributed denial of service Flooding a service with traffic from many machines, which can take domains offline when aimed at DNS. Full definition of DDoS attack hit 10 of the 13 identities, peaked at over one terabit per second and lasted just under ten minutes. The operators’ July 2026 report found no known errors visible to end user A buyer who wants a domain to use it, not to resell it. Full definition of end user, only minor delays for some lookups, and credits the operators’ independence and diversity.

Local copies of the root and why resolvers keep them

A resolver normally starts from root hints The list of root server names and addresses that a resolver starts from. Full definition of root hints, a short list of root server names and addresses, usually built into its software; IANA publishes the official version. At start-up the resolver asks a root server for the current list, a step called priming (RFC 9609, February 2025), because root server addresses occasionally change.

A hyperlocal root A resolver keeping its own copy of the root zone instead of querying root servers. Full definition of hyperlocal root goes further: the resolver keeps a full copy of the root zone on the same machine and answers only itself (RFC 8806, June 2020). The copy must be DNSSEC-validated and identical to the real zone; if it cannot be refreshed in time, the resolver must switch back to the root servers at once. The stated goals are reliability during attacks and privacy. RFC 8806 expects little speed gain for existing TLDs, which are usually cached already, and warns that a faulty setup can give users bad data. A hyperlocal root copies the official zone; an alternative root A DNS root outside the IANA root zone, reachable only with special setup. Full definition of alternative root changes it.

As of 9 October 2026, the key rollover The planned, step-by-step replacement of a DNSSEC signing key. Full definition of key rollover is scheduled for 11 October 2026, when KSK-2024 takes over from KSK-2017. Validating resolvers, hyperlocal roots included, need the updated trust anchor The key a DNSSEC resolver trusts from the start, normally the root zone's key. Full definition of trust anchor.

Sources