Subdomain recursive proxy rules
You can enable subdomain recursive proxy for a domain in Private Zone. When enabled, if a DNS query within the zone's effective scope matches no record, Alibaba Cloud DNS queries the forward zone. If forwarding also returns no result, a public recursive lookup is performed. This topic describes typical use cases for this feature.
Use case 1: No DNS records in the zone
On the Alibaba Cloud DNS - Private Zone page, add the zone
aliyun.comand enable the Subdomain Recursive Proxy.Define the effective scope for the
aliyun.comzone without adding any DNS records.On an ECS instance within the effective VPC, run
dig aliyun.com. The subdomain recursive proxy is triggered, retrieving the DNS record from the public internet.[root@iZm5edhllqvfr02fajnxxx ~]# dig aliyun.com ; <<>> DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.16 <<>> aliyun.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 34584 ;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 0 ;; QUESTION SECTION: ;aliyun.com. IN A ;; ANSWER SECTION: aliyun.com. 10 IN A 106.11.xxx aliyun.com. 10 IN A 106.11.xxx aliyun.com. 10 IN A 106.11.xxx aliyun.com. 10 IN A 106.11.xxx aliyun.com. 10 IN A 140.205.xxx aliyun.com. 10 IN A 140.205.xxx
Use case 2: Adding an @ record on a non-default line
On the Alibaba Cloud DNS - Private Zone page, add the zone
aliyun.comand enable the Subdomain Recursive Proxy.Define the effective scope for the
aliyun.comzone and add a DNS record. Set the hostname to "@" and the query source to a custom ACL. For details, see Custom ACLs. In this example, the record value is10.10.10.10.NoteThis example uses a custom line, but the same logic applies to Alibaba Cloud-defined lines.
On an ECS instance with a source IP address within the CIDR block of the custom ACL, run
dig aliyun.com. The query matches the DNS record configured in the Private Zone.[root@iZm5edhllqvfr02fajxxx ~]# dig aliyun.com ; <<>> DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.16 <<>> aliyun.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 54074 ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1436 ;; QUESTION SECTION: ;aliyun.com. IN A ;; ANSWER SECTION: aliyun.com. 5 IN A 10.10.10.10On an ECS instance with a source IP address outside the CIDR block of the custom ACL, run
dig aliyun.com. The subdomain recursive proxy is not triggered.[root@izm5ec006utwl56ezxxx ~]# dig aliyun.com ; <<>> DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.16 <<>> aliyun.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 16177 ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1436 ;; QUESTION SECTION: ;aliyun.com. IN A ;; AUTHORITY SECTION: aliyun.com. 20 IN SOA ns00.alidns.com. hostmaster.hichina.com. 2024072420 3600 1200 86400 20 ;; Query time: 0 msec ;; SERVER: 100.100.2.136#53(100.100.2.136) ;; WHEN: Wed Jul 24 20:49:11 CST 2024 ;; MSG SIZE rcvd: 112ImportantA hostname of "@" represents the domain itself. The domain always has an SOA record with its query source set to Default. Because the query matches this record, the subdomain recursive proxy is not triggered.
Use case 3: Adding a non-@ record on a non-default line
On the Alibaba Cloud DNS - Private Zone page, add the zone
aliyun.comand enable the Subdomain Recursive Proxy.Define the effective scope for the
aliyun.comzone and add a DNS record. Set the hostname to "www" and the query source to a custom ACL. For details, see Custom ACLs. In this example, the record value is192.168.10.10.On an ECS instance with a source IP address within the CIDR block of the custom ACL, run
dig www.aliyun.com. The query matches the DNS record configured in the Private Zone.[root@iZm5edhllqvfr02fxxx ~]# dig www.aliyun.com ; <<>> DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.16 <<>> www.aliyun.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 47781 ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1436 ;; QUESTION SECTION: ;www.aliyun.com. IN A ;; ANSWER SECTION: www.aliyun.com. 5 IN A 192.168.10.10 ;; Query time: 0 msec ;; SERVER: 100.100.2.136#53(100.100.2.136) ;; WHEN: Thu Jul 25 17:17:54 CST 2024 ;; MSG SIZE rcvd: 59On an ECS instance with a source IP address outside the CIDR block of the custom ACL, run
dig www.aliyun.com. The subdomain recursive proxy is triggered.[root@iZm5ec006utwl56exxx ~]# dig www.aliyun.com ; <<>> DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.16 <<>> www.aliyun.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 25614 ;; flags: qr rd ra; QUERY: 1, ANSWER: 15, AUTHORITY: 0, ADDITIONAL: 0 ;; QUESTION SECTION: ;www.aliyun.com. IN A ;; ANSWER SECTION: www.aliyun.com. 6 IN CNAME www-jp-de-intl-adns.aliyun.com. www-jp-de-intl-adns.aliyun.com. 6 IN CNAME www-jp-de-intl-adns.aliyun.com.gds.alibabadns.com. www-jp-de-intl-adns.aliyun.com.gds.alibabadns.com. 6 IN CNAME www.aliyun.com.w.cdngslb.com. www.aliyun.com.w.cdngslb.com. 6 IN A 114.80.1xx.xxx www.aliyun.com.w.cdngslb.com. 6 IN A 61.170.xx.xxx www.aliyun.com.w.cdngslb.com. 6 IN A 101.226.xxx.xxx www.aliyun.com.w.cdngslb.com. 6 IN A 61.170.xxx.xxx www.aliyun.com.w.cdngslb.com. 6 IN A 180.163.xxx.xxx www.aliyun.com.w.cdngslb.com. 6 IN A 61.170.xxx.xxx www.aliyun.com.w.cdngslb.com. 6 IN A 180.163.1xx.xxx www.aliyun.com.w.cdngslb.com. 6 IN A 180.163.1xx.xxx www.aliyun.com.w.cdngslb.com. 6 IN A 101.226.xxx.xxx www.aliyun.com.w.cdngslb.com. 6 IN A 180.163.1xx.xxx www.aliyun.com.w.cdngslb.com. 6 IN A 49.79.xxx.xxx www.aliyun.com.w.cdngslb.com. 6 IN A 61.170.xxx.xxx ;; Query time: 0 msec ;; SERVER: 100.100.2.136#53(100.100.2.136) ;; WHEN: Thu Jul 25 17:17:40 CST 2024 ;; MSG SIZE rcvd: 373
Proxy rules
The proxy is triggered if a zone has no DNS records.
If the hostname "@" is configured on a non-default line and a DNS query does not match any record in Private Zone, the proxy is not triggered.
If a hostname other than "@" is configured on a non-default line and a DNS query does not match any record in Private Zone, the proxy is triggered.