SOA Lookup
SOA Lookup helps you query start of authority records for zone information, for authoritative DNS validation, resolver checks, and faster troubleshooting.
Advertisement · Anuncio
Advertisement · Anuncio
Technical Analysis & Guide
What It Does
SOA Lookup fetches the Start of Authority record that sits at the top of every DNS zone and breaks it into its seven fields: primary name server, responsible mailbox, serial number and the refresh, retry, expire and minimum timers. These values control how secondary servers synchronize with the primary and how long resolvers remember that a name does not exist.

Why It Matters
- →Replication health: If the serial on one authoritative server lags behind the others, that server is still answering with old data after your change.
- →Negative caching: The minimum field caps how long resolvers cache NXDOMAIN and NODATA answers, which is why a freshly created record can stay invisible for hours.
- →Outage tolerance: The expire timer decides how long secondaries keep serving the zone when the primary is unreachable; set it too low and an outage takes the whole domain down.
- →Provider identification: The MNAME and RNAME reveal which DNS platform actually hosts the zone, useful during audits, transfers and incident response.
- →Change discipline: A serial that never moves suggests changes bypass the normal workflow or that zone transfers are not in use at all.
How to Read Results
- nsname (MNAME): The primary or master name server declared for the zone, e.g. ns1.example.net. Managed DNS providers often show one of their anycast names here.
- hostmaster (RNAME): The administrator mailbox with the first dot standing in for @, so hostmaster.example.com means [email protected].
- serial: A 32-bit version number. Formats such as 2026101001 (YYYYMMDDnn) or a Unix timestamp are conventions; secondaries only care that it increases.
- refresh, retry, expire: Seconds between secondary checks for a new serial, seconds before retrying a failed check, and seconds after which an unreachable primary makes secondaries stop answering.
- minttl: The SOA MINIMUM field, used since RFC 2308 as the upper bound for caching negative answers.
- Status fail or an error: The domain does not exist or the name is not a zone apex. Enter the registered domain (example.com) or a delegated subzone, not an ordinary host such as www.
Technical Background
Every DNS zone begins with exactly one SOA record, defined in RFC 1035 section 3.3.13. In zone-file form it reads: example.com. 3600 IN SOA ns1.example.net. hostmaster.example.com. 2026101001 7200 1800 1209600 3600. The first two fields are names: MNAME, the primary server that holds the master copy of the zone, and RNAME, the responsible mailbox encoded as a domain name. The remaining five are unsigned 32-bit integers that drive zone replication and negative caching. Because the SOA marks a zone cut, it exists only at the apex of a zone; querying an ordinary host name returns no SOA in the answer section, only in the authority section of a negative reply.
The serial number is the version of the zone. Secondary servers poll the primary every refresh seconds, compare serials, and initiate a zone transfer (AXFR, or incremental IXFR per RFC 1995) when the primary's serial is higher. NOTIFY messages (RFC 1996) let the primary trigger that check immediately instead of waiting for refresh. Comparison uses serial-number arithmetic from RFC 1982, so values wrap around modulo 2^32; going backwards is not possible without a deliberate two-step jump. The YYYYMMDDnn convention, e.g. 2026101001 for the first change on 10 October 2026, is human-readable but allows only 100 edits per day. Many managed platforms instead use a Unix timestamp or a simple counter. What matters is that all authoritative servers report the same serial once a change has propagated.
Retry is how long a secondary waits before trying again after a failed refresh, and it should be shorter than refresh. Expire is the safety valve: if a secondary cannot reach the primary for that long, it stops answering for the zone with authority, and the domain begins returning SERVFAIL. Values between one and four weeks (604800 to 2419200 seconds) are common so that a long primary outage does not cascade.
The last field changed meaning over time. RFC 1035 called it MINIMUM, a floor for record TTLs, but RFC 2308 redefined it as the negative-caching TTL. When a resolver receives NXDOMAIN or NODATA, it caches that answer for the lower of the SOA record's own TTL and the MINIMUM value. If MINIMUM is 86400, anyone who looked up a name before you created it may not see the new record for up to a day. Values between 300 and 3600 seconds are a sensible balance for most zones. With managed or anycast DNS, refresh, retry and expire may be cosmetic because the provider replicates internally, yet the negative TTL still applies to every resolver on the internet.
Common Errors and How to Fix Them
- ProblemEdited a zone file on a self-hosted primary but secondaries still serve the old records.
- FixThe serial was not incremented. Raise it (for example from 2026101001 to 2026101002), reload the zone (rndc reload example.com) and confirm every NS reports the new serial.
- ProblemSerial accidentally set to a huge value such as 20261010001 (eleven digits) or decreased.
- FixSecondaries will ignore lower serials. Use RFC 1982 arithmetic: add 2147483647 to wrap, let it transfer, then set the desired value, or force a fresh AXFR on each secondary.
- ProblemNew subdomain is not visible for hours on some networks.
- FixResolvers cached the earlier NXDOMAIN for the SOA MINIMUM period. Lower MINIMUM to 300 to 3600 seconds for future changes and flush the cache of resolvers you control.
- ProblemDomain went down entirely during a long primary outage.
- FixExpire was set very low (for example 3600). Raise it to between 1209600 and 2419200 seconds so secondaries keep answering while the primary is repaired.
- ProblemRNAME written as an email address with @ or with an unescaped dot in the local part.
- FixWrite the mailbox in domain form: hostmaster.example.com. for [email protected]. A dot inside the local part must be escaped, as in john\.doe.example.com.
Frequently Asked Questions
What is a good SOA serial number format?
Any scheme works as long as the number increases with every change. YYYYMMDDnn, such as 2026101001, is popular because you can read the date of the last edit, but it allows only 100 changes per day. Automated platforms often use Unix timestamps. Avoid decreasing the serial, because secondaries will ignore the update.
Why do my name servers show different SOA serials?
One or more secondaries have not yet transferred the latest version of the zone. Check that NOTIFY reaches them, that zone transfers are allowed from their IPs and that they can reach the primary on TCP port 53. Short differences right after a change are normal; persistent ones are not.
What does the SOA minimum TTL control?
Since RFC 2308, it is the maximum time resolvers cache negative answers, meaning NXDOMAIN or a name that exists without the requested type. The effective value is the lower of the SOA record's TTL and this field. It does not set a minimum TTL for other records, despite its historical name.
Do I need to change SOA values on a managed DNS provider?
Usually not. Managed and anycast providers replicate zones internally and update the serial automatically, so refresh, retry and expire rarely matter. The minimum field still affects every resolver's negative caching, so check that it is not excessively high if new records take long to appear.
Why does the SOA lookup fail for www.example.com?
An SOA exists only at the apex of a zone. www is normally a host inside the example.com zone, not a separate zone, so there is no SOA at that name. Query the registered domain instead, or a subdomain that has been delegated with its own NS records.
Academic Documentation
Protocol context and primary references
REST API Documentation
v1.0GET /api/tools/soa-lookup
curl -X POST https://epcybertools.com/api/tools/soa-lookup \
-H "Content-Type: application/json" \
-d '{"domain":"google.com"}'
{
"success": true,
"results": [
{ "test": "Sample Check", "status": "pass", "message": "All clear" }
]
}
Usage Examples
# Full SOA in one line
dig SOA example.com +short
# Compare the serial on every authoritative server
dig example.com +nssearch