Zeronodes

How DNS caching actually works

2026-03-12

People often say a DNS change is “propagating”. Nothing is really being pushed anywhere. Resolvers around the world simply keep the old answer until its time-to-live (TTL) runs out, and then ask again.

TTL is a promise to the cache

Every record carries a TTL in seconds. A resolver that has just fetched A 203.0.113.10 with a TTL of 3600 may serve that answer for up to an hour without asking the authoritative name servers again. Some resolvers cap or extend TTLs, so treat the number as a hint rather than a guarantee.

Negative answers are cached too

If a name did not exist when someone asked, the “no such name” answer is cached as well, for a time taken from the zone’s SOA record. Creating a record right after a failed lookup can therefore look broken for a while.

Before a migration

Lower the TTL of the records you plan to change a day or two in advance, make the change, check from several networks, and raise the TTL back once things are stable. Lowering it at the last minute does not help, because caches already hold the old value with the old TTL.

← All notes