Enregistrement SOA

Start of Authority — metadata about the zone, including serial, refresh, retry and minimum TTL.

Qu'est-ce qu'un enregistrement SOA ?

There is exactly one SOA per zone. It declares the primary name server, the responsible person's email (in DNS notation), and the timers that govern how secondaries refresh and how negative answers are cached.

Exemple de fichier de zone

example.com. 86400 IN SOA ns1.example.com. hostmaster.example.com. (
  2026010101 ; serial
  3600       ; refresh
  600        ; retry
  604800     ; expire
  300        ; minimum TTL )

Cas d'usage courants

  • Diagnose stale secondaries by comparing their SOA serial to the master.
  • Set the minimum TTL for negative caching (RFC 2308) — prevents NXDOMAIN storms.
  • Audit zone changes: monotonic serial increments on every edit.
  • Validate ownership when transferring a zone between providers.

Pièges courants

The SOA serial must increase on every change, even after a reset. Many issues stem from forgetting to bump it. Format YYYYMMDDnn is conventional but not mandated.

Interroger les enregistrements DNS →

Types d'enregistrement liés

CONSEIL SÉCURITÉ

Vous utilisez des mots de passe par défaut ? Protégez votre réseau avec le chiffrement NordVPN.