Authoritative DNS servers are the actual source of truth for a domain's records — every other part of the DNS system, including recursive resolvers, is ultimately trying to reach these servers (directly or via cache) to get a genuine answer.

Zones and delegation

A domain's records live in a DNS zone, managed by whoever controls that domain. Larger domains often delegate subdomains to separate zones with their own authoritative servers — a structure that lets different parts of a large organization manage their own DNS independently while still fitting into the overall hierarchy.

Records and name servers

The zone's name servers hold the actual records — A and AAAA records for IPv4/IPv6 addresses, MX records for mail routing, and various other record types — each with its own TTL controlling how long resolvers may cache it before checking again.

Primary and secondary servers

For reliability, most domains run multiple authoritative name servers — typically one primary (where changes are actually made) and one or more secondaries that replicate the primary's data. This redundancy means a domain's DNS doesn't go down if a single server has an outage.

Why authoritative servers don't "browse the internet" for you

A common point of confusion: authoritative servers only answer queries about the specific domain(s) they're responsible for — they don't perform lookups on a user's behalf the way a recursive resolver does. They're the destination of a lookup chain, not a participant in initiating one.

FAQ

Who controls a domain's authoritative servers?

Whoever manages the domain's DNS configuration — typically set via the domain registrar or a DNS management service, pointing to the actual name servers that hold the records.