Recursive resolution proxy for subdomains

Updated at:

Private Zone resolves DNS queries through a defined lookup order. You can enable recursive resolution proxy for subdomains to resolve unconfigured subdomains through public DNS.

How it works

image
Note

If the record value of a CNAME record is the same as the domain name being queried, a CNAME resolution loop occurs. The system immediately stops the process and returns the result.

  • A client on the private network sends a domain name resolution query. The query first checks for DNS records in Private Authoritative Zone. If the result is a CNAME record, a new query is sent to resolve the domain name in the CNAME record. Otherwise, the result is returned.

  • If the query is not resolved in Private Authoritative Zone, the system checks the query cache. If the cache contains a DNS record for the domain name that has not expired, that record is used as the result. If the result is a CNAME record, a new query is sent to resolve the domain name in the CNAME record. Otherwise, the result is returned.

  • If the query results in a cache miss, the system checks whether the query matches a domain forward rule. If a rule is matched, the query is forwarded to an external DNS for resolution. If the result is a CNAME record, a new query is sent to resolve the domain name in the CNAME record. Otherwise, the result is returned.

  • If the query does not match a forward rule, the system performs a recursive resolution query on the public network. If the result is a CNAME record, a new query is sent to resolve the domain name in the CNAME record. Otherwise, the result is returned.

Recursive resolution proxy for subdomains

With Subdomain Recursive Proxy enabled, Private Zone performs a public recursive resolution for any subdomain not configured in the Private Zone and returns the result to the VPC.

For example, the zone name is aliyun.com, and three private records are configured in aliyun.com as shown in the following table:

Hostname

Type

TTL

Value

host01

A

60

10.0.0.1

host02

A

60

10.0.0.2

host03

A

60

10.0.0.3

  • Queries for host01.aliyun.com, host02.aliyun.com, or host03.aliyun.com return the configured private IP addresses 10.0.0.1, 10.0.0.2, and 10.0.0.3, respectively.

  • Queries for public domain names, such as www.aliyun.com, api.aliyun.com, or rds.aliyun.com, are resolved through public recursive resolution. Private Zone returns the public DNS result as the final response.

Enable or disable feature

You can enable or disable recursive resolution proxy for subdomains when you add a Private Zone. For more information, see Add an Authoritative Zone.

  1. Log on to the Alibaba Cloud DNS - Private Zone console.

  2. In the left-side navigation pane, click User Defined Zones. Then, find and click the domain name that you want to manage.

  3. Click the Zone Settings tab. In the Subdomain Recursive Proxy section, toggle the switch to enable or disable the feature.

Note

Enabling the feature does not affect the resolution of your existing DNS records.