Subdomain recursive proxy rules

Updated at:

You can enable subdomain recursive proxy for a domain in Private Zone. When enabled, if a DNS query within the zone's effective scope matches no record, Alibaba Cloud DNS queries the forward zone. If forwarding also returns no result, a public recursive lookup is performed. This topic describes typical use cases for this feature.

Use case 1: No DNS records in the zone

  1. On the Alibaba Cloud DNS - Private Zone page, add the zone aliyun.com and enable the Subdomain Recursive Proxy.

  2. Define the effective scope for the aliyun.com zone without adding any DNS records.

  3. On an ECS instance within the effective VPC, run dig aliyun.com. The subdomain recursive proxy is triggered, retrieving the DNS record from the public internet.

    [root@iZm5edhllqvfr02fajnxxx ~]# dig aliyun.com
    
    ; <<>> DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.16 <<>> aliyun.com
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 34584
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 0
    
    ;; QUESTION SECTION:
    ;aliyun.com.                    IN      A
    
    ;; ANSWER SECTION:
    aliyun.com.             10      IN      A       106.11.xxx
    aliyun.com.             10      IN      A       106.11.xxx
    aliyun.com.             10      IN      A       106.11.xxx
    aliyun.com.             10      IN      A       106.11.xxx
    aliyun.com.             10      IN      A       140.205.xxx
    aliyun.com.             10      IN      A       140.205.xxx
              

Use case 2: Adding an @ record on a non-default line

  1. On the Alibaba Cloud DNS - Private Zone page, add the zone aliyun.com and enable the Subdomain Recursive Proxy.

  2. Define the effective scope for the aliyun.com zone and add a DNS record. Set the hostname to "@" and the query source to a custom ACL. For details, see Custom ACLs. In this example, the record value is 10.10.10.10.

    Note

    This example uses a custom line, but the same logic applies to Alibaba Cloud-defined lines.

  3. On an ECS instance with a source IP address within the CIDR block of the custom ACL, run dig aliyun.com. The query matches the DNS record configured in the Private Zone.

    [root@iZm5edhllqvfr02fajxxx ~]# dig aliyun.com
    
    ; <<>> DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.16 <<>> aliyun.com
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 54074
    ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
    
    ;; OPT PSEUDOSECTION:
    ; EDNS: version: 0, flags:; udp: 1436
    ;; QUESTION SECTION:
    ;aliyun.com.                    IN      A
    
    ;; ANSWER SECTION:
    aliyun.com.             5       IN      A       10.10.10.10
              
  4. On an ECS instance with a source IP address outside the CIDR block of the custom ACL, run dig aliyun.com. The subdomain recursive proxy is not triggered.

    [root@izm5ec006utwl56ezxxx ~]# dig aliyun.com
    
    ; <<>> DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.16 <<>> aliyun.com
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 16177
    ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
    
    ;; OPT PSEUDOSECTION:
    ; EDNS: version: 0, flags:; udp: 1436
    ;; QUESTION SECTION:
    ;aliyun.com.			IN	A
    
    ;; AUTHORITY SECTION:
    aliyun.com.		20	IN	SOA	ns00.alidns.com. hostmaster.hichina.com. 2024072420 3600 1200 86400 20
    
    ;; Query time: 0 msec
    ;; SERVER: 100.100.2.136#53(100.100.2.136)
    ;; WHEN: Wed Jul 24 20:49:11 CST 2024
    ;; MSG SIZE  rcvd: 112
              
    Important

    A hostname of "@" represents the domain itself. The domain always has an SOA record with its query source set to Default. Because the query matches this record, the subdomain recursive proxy is not triggered.

Use case 3: Adding a non-@ record on a non-default line

  1. On the Alibaba Cloud DNS - Private Zone page, add the zone aliyun.com and enable the Subdomain Recursive Proxy.

  2. Define the effective scope for the aliyun.com zone and add a DNS record. Set the hostname to "www" and the query source to a custom ACL. For details, see Custom ACLs. In this example, the record value is 192.168.10.10.

  3. On an ECS instance with a source IP address within the CIDR block of the custom ACL, run dig www.aliyun.com. The query matches the DNS record configured in the Private Zone.

    [root@iZm5edhllqvfr02fxxx ~]# dig www.aliyun.com
    
    ; <<>> DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.16 <<>> www.aliyun.com
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 47781
    ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
    
    ;; OPT PSEUDOSECTION:
    ; EDNS: version: 0, flags:; udp: 1436
    ;; QUESTION SECTION:
    ;www.aliyun.com.                IN      A
    
    ;; ANSWER SECTION:
    www.aliyun.com.         5       IN      A       192.168.10.10
    
    ;; Query time: 0 msec
    ;; SERVER: 100.100.2.136#53(100.100.2.136)
    ;; WHEN: Thu Jul 25 17:17:54 CST 2024
    ;; MSG SIZE  rcvd: 59
              
  4. On an ECS instance with a source IP address outside the CIDR block of the custom ACL, run dig www.aliyun.com. The subdomain recursive proxy is triggered.

    [root@iZm5ec006utwl56exxx ~]# dig www.aliyun.com
    
    ; <<>> DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.16 <<>> www.aliyun.com
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 25614
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 15, AUTHORITY: 0, ADDITIONAL: 0
    
    ;; QUESTION SECTION:
    ;www.aliyun.com.                IN      A
    
    ;; ANSWER SECTION:
    www.aliyun.com.         6       IN      CNAME   www-jp-de-intl-adns.aliyun.com.
    www-jp-de-intl-adns.aliyun.com. 6 IN    CNAME   www-jp-de-intl-adns.aliyun.com.gds.alibabadns.com.
    www-jp-de-intl-adns.aliyun.com.gds.alibabadns.com. 6 IN CNAME www.aliyun.com.w.cdngslb.com.
    www.aliyun.com.w.cdngslb.com. 6 IN      A       114.80.1xx.xxx
    www.aliyun.com.w.cdngslb.com. 6 IN      A       61.170.xx.xxx
    www.aliyun.com.w.cdngslb.com. 6 IN      A       101.226.xxx.xxx
    www.aliyun.com.w.cdngslb.com. 6 IN      A       61.170.xxx.xxx
    www.aliyun.com.w.cdngslb.com. 6 IN      A       180.163.xxx.xxx
    www.aliyun.com.w.cdngslb.com. 6 IN      A       61.170.xxx.xxx
    www.aliyun.com.w.cdngslb.com. 6 IN      A       180.163.1xx.xxx
    www.aliyun.com.w.cdngslb.com. 6 IN      A       180.163.1xx.xxx
    www.aliyun.com.w.cdngslb.com. 6 IN      A       101.226.xxx.xxx
    www.aliyun.com.w.cdngslb.com. 6 IN      A       180.163.1xx.xxx
    www.aliyun.com.w.cdngslb.com. 6 IN      A       49.79.xxx.xxx
    www.aliyun.com.w.cdngslb.com. 6 IN      A       61.170.xxx.xxx
    
    ;; Query time: 0 msec
    ;; SERVER: 100.100.2.136#53(100.100.2.136)
    ;; WHEN: Thu Jul 25 17:17:40 CST 2024
    ;; MSG SIZE  rcvd: 373
              

Proxy rules

  • The proxy is triggered if a zone has no DNS records.

  • If the hostname "@" is configured on a non-default line and a DNS query does not match any record in Private Zone, the proxy is not triggered.

  • If a hostname other than "@" is configured on a non-default line and a DNS query does not match any record in Private Zone, the proxy is triggered.