+91 98726 60544 hello@mitstech.co Mon–Sat · 09:00–18:30 IST

DNS: the single point of failure nobody owns

IT Services By Mits IT Practice 1 min read
DNS: the single point of failure nobody owns

Ask who owns your domain registration and you will often get a pause. It was registered years ago, possibly by an agency, possibly on a personal credit card belonging to someone who has left. The renewal notice goes to an address nobody reads.

That is a company-ending risk disguised as an administrative detail. A lapsed domain takes down the website, the email and every system that authenticates against it, simultaneously, and recovering a domain that has been released is not always possible.

Fix the boring things first. Registration in the company's name, not an individual's. Auto-renewal enabled and paid on a card that will not expire. Registrar lock switched on to prevent unauthorised transfer. Renewal notices going to a distribution list rather than a person. Two people with access.

Then look at resilience. A single DNS provider is a single point of failure, and provider outages have taken large portions of the internet offline more than once. Secondary DNS with a second provider is available cheaply and removes that dependency, at the cost of keeping two zones in sync.

Time-to-live values are the lever you will wish you had set correctly. A long TTL means changes propagate slowly, which is exactly wrong during an incident when you need to fail over. Lowering TTLs in advance of any planned migration is a small step that saves hours.

Finally, document the zone. A DNS zone accumulates records over years — old verification strings, mail routing for services long cancelled, subdomains pointing at servers that no longer exist. Reviewing it annually removes both confusion and, occasionally, a subdomain an attacker could take over.

Back to all news

Keep reading

More on IT Services