DNS Stub Zones

DNS stub zones are used to enable your DNS servers to resolve records in another domain. The information in the stub zone allows your DNS to contact the authoritative DNS server directly.

This does sound a bit like conditional forwarding, and actually it is! For a better understanding, let’s look at the difference between stub zones and conditional forwarding.

Conditional Forwarding vs Stub Zones

In conditional forwarding you hardcode your DNS server with the IP addresses used to contact the authoritative DNS servers. If one of the DNS servers change, your conditional forwarding will start to fail. If a new DNS server is introduced, your DNS server will never find out and therefore won’t start using it.

In a stub zone the forwarding IP(s) are used to retrieve the NS records of the authoritative domain as well as the A records needed to resolve the hostnames in the NS records. By the way, these A records are referred to as glue records.

Your DNS server will continue to look at the NS records on the authoritative DNS server and if they change this is reflected in your stub zone. This means that if a DNS server changes, your stub zone forwarding will become aware of this. If a new DNS server is introduced, your DNS server will automatically start using that new server.

Contents of Stub Zone and Caching

The stub zone will always keep just the information needed to contact the authoritative DNS servers. This means the NS records and the A records needed to resolve the NS records.

Any host records in the domain zone of the authoritative DNS servers are cached on your DNS server like any other records that are resolved on external DNS: They are stored in your local DNS cache for the duration of the TTL set on the DNS record.

How to Configure a Stub Zone

To configure a stub zone follow this step-by-step guide:

1. Create a new zone:

DNS Stub Zone

Click next on the wizard welcome screen:

DNS Stub zone

Choose to create a stub zone:

DNS Stub zone

Select the replication scope of the stub zone:

DNS Stub Zone

Select the domain name for this stub zone:

DNS Stub Zone

Insert one or more name servers from where to load the zone info. Notice that zone transfer must be allowed:

DNS Stub zone

Review settings and complete the wizard:

DNS Stub Zone

And voila! The stub zone has been created:

DNS Stub zone


Hopefully it’s now clear what DNS stub zones are, how they differ from conditional forwarding and how you can implement them via the DNS management console.

Want to learn about more advanced DNS features? Check out this article which discusses high availability using Azure DNS Traffic Manager and AWS Route 53. 

