resolver: a domain's nameservers are only its own delegation (closes #222)
check / check (push) Canceled after 0s

LookupNS now follows the delegation for the domain alone. When the parent
zone's servers answer that it has no delegation, as for a domain that does
not exist, the set is empty, and the watcher's NS comparison reports every
nameserver removed.

FindAuthoritativeNameservers, used for hostnames, still moves to a parent
name when the servers answer that the name has no delegation of its own,
but returns the error when they do not answer, where it used to take a
parent zone's nameservers. The fallback walk treats an authoritative
answer the same way.

A domain with no delegation still has its own records asked at the
servers of the zone it is in.

Model: opus-5-5
This commit is contained in:
2026-10-02 08:56:31 +00:00
parent 9b9e26d6b2
commit 65b3212e9d
6 changed files with 104 additions and 27 deletions
+13 -4
View File
@@ -73,9 +73,13 @@ notification endpoint set, changes show only on the dashboard; see
to discover all authoritative nameservers (NS records) for each domain.
- Queries **every** discovered authoritative nameserver independently.
- Stores the domain's NS record set, as its parent zone's servers delegate it,
and the IPv4 and IPv6 addresses each nameserver's name resolves to.
and the IPv4 and IPv6 addresses each nameserver's name resolves to. The set is
only ever the domain's own delegation: a domain that its parent zone's servers
answer does not exist, or has no delegation, has no nameservers. When they do
not answer, the check fails and the set from the previous check is kept.
- Any change triggers a notification:
- NS added to or removed from that set.
- NS added to or removed from that set. A domain that had nameservers on the
previous check and no longer exists gets one with all of them removed.
- NS address change: a nameserver that stays in the set resolves to
different addresses than on the previous check. A nameserver added or
removed gets only the NS change notification. When the lookup of a
@@ -87,7 +91,9 @@ notification endpoint set, changes show only on the dashboard; see
records, stored per nameserver. Their changes are notified as a hostname's
are, as a record change, NS query failure, NS recovery, inconsistency or CNAME
address change, in a message that starts `Domain:` where a hostname's starts
`Hostname:`.
`Hostname:`. A domain with no nameservers of its own has these records asked
at the servers of the zone it is in, as a hostname has: for a `.com` domain
that does not exist, the `.com` servers, which answer that it does not exist.
### DNS Hostname Monitoring (Subdomains)
@@ -95,7 +101,10 @@ notification endpoint set, changes show only on the dashboard; see
via the Public Suffix List).
- Every **1 hour** by default, performs a full iterative trace to discover the
authoritative nameservers of the zone the hostname is in, which is not always
its last two labels (a name under `co.uk`, or in a delegated subdomain).
its last two labels (a name under `co.uk`, or in a delegated subdomain). The
trace moves from a name to its parent only when the servers asked answer that
the name has no delegation of its own. When they do not answer, the check
fails and the hostname's records from the previous check are kept.
- Queries **each** authoritative nameserver independently for **all** record
types: A, AAAA, CNAME, MX, TXT, SRV, CAA, NS.
- Each record type is a query of its own. When a nameserver answers some types