Recursive resolution proxy for subdomains
Private Zone resolves DNS queries through a defined lookup order. You can enable recursive resolution proxy for subdomains to resolve unconfigured subdomains through public DNS.
How it works
If the record value of a CNAME record is the same as the domain name being queried, a CNAME resolution loop occurs. The system immediately stops the process and returns the result.
A client on the private network sends a domain name resolution query. The query first checks for DNS records in Private Authoritative Zone. If the result is a CNAME record, a new query is sent to resolve the domain name in the CNAME record. Otherwise, the result is returned.
If the query is not resolved in Private Authoritative Zone, the system checks the query cache. If the cache contains a DNS record for the domain name that has not expired, that record is used as the result. If the result is a CNAME record, a new query is sent to resolve the domain name in the CNAME record. Otherwise, the result is returned.
If the query results in a cache miss, the system checks whether the query matches a domain forward rule. If a rule is matched, the query is forwarded to an external DNS for resolution. If the result is a CNAME record, a new query is sent to resolve the domain name in the CNAME record. Otherwise, the result is returned.
If the query does not match a forward rule, the system performs a recursive resolution query on the public network. If the result is a CNAME record, a new query is sent to resolve the domain name in the CNAME record. Otherwise, the result is returned.
Recursive resolution proxy for subdomains
With Subdomain Recursive Proxy enabled, Private Zone performs a public recursive resolution for any subdomain not configured in the Private Zone and returns the result to the VPC.
Hostname | Type | TTL | Value |
host01 | A | 60 | 10.0.0.1 |
host02 | A | 60 | 10.0.0.2 |
host03 | A | 60 | 10.0.0.3 |
Queries for
host01.aliyun.com, host02.aliyun.com, or host03.aliyun.comreturn the configured private IP addresses10.0.0.1, 10.0.0.2, and 10.0.0.3, respectively.Queries for public domain names, such as
www.aliyun.com, api.aliyun.com, or rds.aliyun.com, are resolved through public recursive resolution. Private Zone returns the public DNS result as the final response.
Enable or disable feature
You can enable or disable recursive resolution proxy for subdomains when you add a Private Zone. For more information, see Add an Authoritative Zone.
Log on to the Alibaba Cloud DNS - Private Zone console.
In the left-side navigation pane, click User Defined Zones. Then, find and click the domain name that you want to manage.
Click the Zone Settings tab. In the Subdomain Recursive Proxy section, toggle the switch to enable or disable the feature.
Enabling the feature does not affect the resolution of your existing DNS records.