{"id":13250,"date":"2025-12-20T11:06:57","date_gmt":"2025-12-20T05:36:57","guid":{"rendered":"https:\/\/www.youstable.com\/blog\/?p=13250"},"modified":"2026-09-07T11:12:02","modified_gmt":"2026-09-07T05:42:02","slug":"use-dns-on-linux","status":"publish","type":"post","link":"https:\/\/www.youstable.com\/blog\/use-dns-on-linux\/","title":{"rendered":"How to Use DNS on Linux Server? Linux DNS Guide"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>DNS on a Linux server<\/strong> lets you resolve domain names to IPs and optionally host your own DNS zones. To use DNS, configure resolvers for your system (resolv.conf or systemd resolved), install tools like dig, optionally run a caching resolver (Unbound), or deploy an authoritative server (BIND9) to host records and zones.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re wondering how to use DNS on Linux server environments, this guide walks you through client side resolution, caching resolvers, and full authoritative DNS with BIND9. You\u2019ll learn essential commands, secure configurations, and real world tips from production hosting scenarios so you can resolve, serve, and troubleshoot DNS confidently.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"what-is-dns-and-why-it-matters-on-a-linux-server\">What is DNS and Why it Matters on a Linux Server?<\/h2>\n\n\n\n<div class=\"wp-block-media-text has-media-on-the-right is-stacked-on-mobile\"><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">DNS (Domain Name System) translates human readable domains (example.com) into IP addresses. On Linux, you\u2019ll typically deal with:<\/p>\n<\/div><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1168\" height=\"784\" src=\"https:\/\/www.youstable.com\/blog\/wp-content\/uploads\/2025\/12\/What-Is-DNS-and-Why-It-Matters-on-a-Linux-Server.png\" alt=\"What Is DNS and Why It Matters on a Linux Server\" class=\"wp-image-13596 size-full\" srcset=\"https:\/\/www.youstable.com\/blog\/wp-content\/uploads\/2025\/12\/What-Is-DNS-and-Why-It-Matters-on-a-Linux-Server.png 1168w, https:\/\/www.youstable.com\/blog\/wp-content\/uploads\/2025\/12\/What-Is-DNS-and-Why-It-Matters-on-a-Linux-Server-150x101.png 150w\" sizes=\"auto, (max-width: 1168px) 100vw, 1168px\" \/><\/figure><\/div>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Resolvers<\/strong> (clients): Your server queries upstream DNS to resolve names.<\/li>\n\n\n\n<li><strong>Caching resolvers<\/strong>: Locally cache answers to speed lookups and reduce latency.<\/li>\n\n\n\n<li><strong>Authoritative servers<\/strong>: Host DNS records for your domains and answer queries for those zones.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Common use cases include speeding up application lookups, providing internal name resolution for private networks, or hosting public DNS for websites and mail.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"quick-start-use-dns-on-linux-as-a-client\">Quick Start: Use DNS on Linux as a Client<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Most servers only need to query DNS. Here\u2019s how to configure resolvers and verify resolution.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"check-your-current-dns-resolvers\">Check Your Current DNS Resolvers<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Modern distributions often use systemd resolved. Check the active configuration:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>resolvectl status\ncat \/etc\/resolv.conf<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If \/etc\/resolv.conf is a symlink to systemd resolved, manage DNS with resolvectl or your network stack (NetworkManager, netplan).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"set-dns-servers-ubuntu-debian\">Set DNS Servers (Ubuntu\/Debian)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>On Ubuntu using netplan:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nano \/etc\/netplan\/01-netcfg.yaml\n# Example snippet:\n# network:\n#   version: 2\n#   ethernets:\n#     eth0:\n#       addresses: &#91;203.0.113.10\/24]\n#       gateway4: 203.0.113.1\n#       nameservers:\n#         addresses: &#91;1.1.1.1,8.8.8.8]\n\nsudo netplan apply<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>On Debian or older Ubuntu with NetworkManager:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmcli con mod \"System eth0\" ipv4.dns \"1.1.1.1 8.8.8.8\"\nnmcli con up \"System eth0\"<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"set-dns-servers-rhel-centos-almalinux-rocky\">Set DNS Servers (RHEL\/CentOS\/AlmaLinux\/Rocky)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Using NetworkManager:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nmcli con mod eth0 ipv4.dns \"9.9.9.9 1.1.1.1\"\nnmcli con up eth0<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>If you must edit \/etc\/resolv.conf directly (not recommended with systemd resolved):<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nano \/etc\/resolv.conf\n# Example:\n# nameserver 1.1.1.1\n# nameserver 8.8.8.8<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"test-dns-resolution\">Test DNS Resolution<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Install tools and query:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Debian\/Ubuntu\nsudo apt update &amp;&amp; sudo apt install dnsutils -y\n\n# RHEL family\nsudo dnf install bind-utils -y\n\n# Tests\ndig example.com +short\ndig A example.com @1.1.1.1 +short\nnslookup example.com\ngetent hosts example.com<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"set-up-a-caching-dns-resolver\">Set Up a Caching DNS Resolver<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A local caching resolver reduces latency and improves reliability. Two common approaches are systemd resolved\u2019s cache and Unbound.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"enable-systemd-resolved-caching\">Enable systemd resolved Caching<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">systemd resolved can run a local stub at 127.0.0.53. Verify and point your system to it:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo systemctl enable --now systemd-resolved\nresolvectl status\n# Ensure \/etc\/resolv.conf symlinks to \/run\/systemd\/resolve\/stub-resolv.conf<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Then specify upstream DNS servers (e.g., Cloudflare, Google, your ISP) via netplan or nmcli, as shown above. systemd resolved will cache responses locally.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"install-unbound-recommended-for-advanced-caching-plus-dnssec\">Install Unbound (Recommended for Advanced Caching + DNSSEC)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Unbound is a lightweight, secure recursive resolver with DNSSEC validation.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Debian\/Ubuntu\nsudo apt install unbound -y\n\n# RHEL\/CentOS\/Alma\/Rocky\nsudo dnf install unbound -y\n\n# Basic config\nsudo nano \/etc\/unbound\/unbound.conf.d\/caching.conf\n# Example:\n# server:\n#   interface: 0.0.0.0\n#   access-control: 127.0.0.0\/8 allow\n#   access-control: 10.0.0.0\/8 allow\n#   prefetch: yes\n#   cache-min-ttl: 60\n#   msg-cache-size: 128m\n#   rrset-cache-size: 256m\n#   harden-dnssec-stripped: yes\n#   do-ip4: yes\n#   do-ip6: no\n#   hide-identity: yes\n#   hide-version: yes\n\nsudo systemctl enable --now unbound\ndig @127.0.0.1 example.com +short<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Point your server\u2019s DNS to 127.0.0.1 for fast local resolution. Consider enabling DNS over TLS upstreams if required for privacy.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"configure-an-authoritative-dns-server-with-bind9\">Configure an Authoritative DNS Server with BIND9<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you host domains, BIND9 (named) is the industry standard authoritative DNS server on Linux. Below is a minimal, secure setup to serve a public zone.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"install-bind9\">Install BIND9<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># Debian\/Ubuntu\nsudo apt update &amp;&amp; sudo apt install bind9 bind9-utils -y\n\n# RHEL family\nsudo dnf install bind bind-utils -y\nsudo systemctl enable --now named<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"bind9-core-configuration\">BIND9 Core Configuration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Edit named.conf.options and named.conf.local (Debian\/Ubuntu) or named.conf (RHEL). Disable recursion on an authoritative-only server.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \/etc\/bind\/named.conf.options (Debian\/Ubuntu)\noptions {\n    directory \"\/var\/cache\/bind\";\n    recursion no;           \/\/ Authoritative only\n    allow-query { any; };\n    dnssec-validation no;   \/\/ Not needed for authoritative-only\n    listen-on { any; };\n    listen-on-v6 { none; };\n};<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"create-a-forward-zone\">Create a Forward Zone<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Define the zone and its zone file:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \/etc\/bind\/named.conf.local\nzone \"example.com\" {\n    type master;\n    file \"\/etc\/bind\/zones\/db.example.com\";\n    allow-transfer { none; }; \/\/ Adjust if using secondary servers\n};<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Now create the zone file with essential records:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo mkdir -p \/etc\/bind\/zones\nsudo nano \/etc\/bind\/zones\/db.example.com\n; \/etc\/bind\/zones\/db.example.com\n$TTL 3600\n@   IN SOA ns1.example.com. admin.example.com. (\n        2025010101 ; Serial (YYYYMMDDNN)\n        3600       ; Refresh\n        900        ; Retry\n        1209600    ; Expire\n        300 )      ; Negative Cache TTL\n\n; NS records\n@       IN NS  ns1.example.com.\n@       IN NS  ns2.example.com.\n\n; A\/AAAA records\nns1     IN A   203.0.113.10\nns2     IN A   203.0.113.11\n@       IN A   203.0.113.20\nwww     IN CNAME @\n\n; Mail (MX) records\n@       IN MX 10 mail.example.com.\nmail    IN A   203.0.113.30\n\n; TXT (SPF) example\n@       IN TXT \"v=spf1 a mx ~all\"<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"create-a-reverse-zone-ptr\">Create a Reverse Zone (PTR)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Serve PTR records if you control the IP block or operate an internal DNS.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \/etc\/bind\/named.conf.local (add)\nzone \"113.0.203.in-addr.arpa\" {\n    type master;\n    file \"\/etc\/bind\/zones\/db.203.0.113\";\n    allow-transfer { none; };\n}\n\n# \/etc\/bind\/zones\/db.203.0.113\n$TTL 3600\n@   IN SOA ns1.example.com. admin.example.com. (\n        2025010101 3600 900 1209600 300 )\n    IN NS ns1.example.com.\n\n10  IN PTR ns1.example.com.\n11  IN PTR ns2.example.com.\n20  IN PTR example.com.\n30  IN PTR mail.example.com.<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Validate and start:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>named-checkconf\nnamed-checkzone example.com \/etc\/bind\/zones\/db.example.com\nsudo systemctl enable --now bind9\nsudo systemctl restart bind9<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"firewall-and-public-reachability\">Firewall and Public Reachability<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Allow DNS (TCP\/UDP 53):<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># ufw\nsudo ufw allow 53\n# firewalld\nsudo firewall-cmd --add-service=dns --permanent\nsudo firewall-cmd --reload<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Update your domain registrar\u2019s nameservers to ns1.example.com and ns2.example.com, ensuring glue records exist for your hostnames.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"security-best-practices-for-linux-dns\">Security Best Practices for Linux DNS<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"separate-roles-authoritative-vs-recursive\">Separate Roles: Authoritative vs Recursive<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do not run open recursion on a public authoritative server. Use separate instances or views. For authoritative only BIND, set recursion no; as shown.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"access-control-and-rate-limiting\">Access Control and Rate Limiting<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Restrict who can query recursion with ACLs and consider Response Rate Limiting (RRL) modules to mitigate abuse.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"secure-zone-transfers\">Secure Zone Transfers<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Permit transfers only to known secondary servers and use TSIG keys for integrity.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"dnssec\">DNSSEC<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Enable DNSSEC validation on resolvers (e.g., Unbound) and sign zones on authoritative servers if you control the domain. Keep keys safe and automate resigning.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"troubleshooting-dns-on-linux\">Troubleshooting DNS on Linux<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"diagnose-with-dig-and-drill\">Diagnose with dig and drill<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>dig example.com +trace\ndig NS example.com @a.root-servers.net\ndig -x 203.0.113.20 +short\ndrill example.com<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"common-errors\">Common Errors<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>SERVFAIL<\/strong>: Often DNSSEC, lame delegation, or upstream timeout.<\/li>\n\n\n\n<li><strong>NXDOMAIN<\/strong>: Record or zone does not exist.<\/li>\n\n\n\n<li><strong>Timeout<\/strong>: Firewall blocking UDP\/TCP 53, or upstream unreachable.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"check-logs-and-flush-caches\">Check Logs and Flush Caches<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># BIND logs (systemd)\njournalctl -u bind9 -f\njournalctl -u named -f\n\n# systemd-resolved\njournalctl -u systemd-resolved -f\nresolvectl flush-caches\n\n# Unbound\njournalctl -u unbound -f\nsudo unbound-control flush_zone example.com<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"performance-tips\">Performance Tips<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Use a caching layer<\/strong>: Unbound or systemd resolved reduces query latency.<\/li>\n\n\n\n<li><strong>Tune cache<\/strong>: Increase rrset and message cache sizes for busy servers.<\/li>\n\n\n\n<li><strong>Choose reliable upstreams<\/strong>: Anycast resolvers (1.1.1.1, 8.8.8.8, 9.9.9.9) or your ISP\u2019s low latency DNS.<\/li>\n\n\n\n<li><strong>Keep TTLs realistic<\/strong>: Lower TTLs (e.g., 300\u2013900s) help during migrations; raise later for fewer queries.<\/li>\n\n\n\n<li><strong>Monitor<\/strong>: Graph query rates, cache hit ratio, and NXDOMAIN spikes to catch issues early.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"when-to-use-managed-dns-or-hosting\">When to Use Managed DNS or Hosting<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Running BIND9 is powerful but adds operational overhead. For most businesses, using a reliable managed DNS or your <a href=\"https:\/\/www.youstable.com\/blog\/best-web-hosting-provider-in-india\/\">hosting provider\u2019s<\/a> DNS panel is simpler and safer. With YouStable hosting, you get a DNS zone editor, fast global resolvers, and 24\u00d77 support\u2014so you can focus on your apps, not nameserver upkeep.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"essential-dns-records-cheat-sheet\">Essential DNS Records Cheat Sheet<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>A\/AAAA<\/strong>: Map hostname to IPv4\/IPv6.<\/li>\n\n\n\n<li><strong>MX<\/strong>: Mail exchanger for your domain.<\/li>\n\n\n\n<li><strong>CNAME<\/strong>: Alias to another hostname.<\/li>\n\n\n\n<li><strong>NS<\/strong>: Authoritative nameservers for a zone.<\/li>\n\n\n\n<li><strong>TXT<\/strong>: SPF, DKIM, verification tokens.<\/li>\n\n\n\n<li><strong>PTR<\/strong>: Reverse mapping IP to hostname.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"step-by-step-from-zero-to-working-dns\">Step-by-Step: From Zero to Working DNS<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Configure system resolvers (resolv.conf, netplan, or nmcli).<\/li>\n\n\n\n<li>Install tools (dig, nslookup) and test resolution.<\/li>\n\n\n\n<li><strong>Optional:<\/strong> Deploy Unbound for a local caching resolver.<\/li>\n\n\n\n<li>If hosting domains: Install BIND9, create forward and reverse zones, and validate configs.<\/li>\n\n\n\n<li>Open firewall ports 53 (UDP\/TCP), set registrar nameservers, and verify with dig +trace.<\/li>\n\n\n\n<li>Harden (no open recursion, ACLs), monitor logs, and implement DNSSEC where appropriate.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"faqs\">FAQs<\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1765793637220\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"whats-the-difference-between-a-dns-resolver-and-an-authoritative-server\">What\u2019s the difference between a DNS resolver and an authoritative server?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>A resolver queries other DNS servers to answer your lookups and often caches results. An authoritative server hosts your domain\u2019s zone files and provides the final, official answers for records like A, MX, and NS.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765793654610\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"should-i-edit-etc-resolv-conf-directly\">Should I edit \/etc\/resolv.conf directly?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Only if you\u2019re not using systemd resolved or NetworkManager. On modern Linux, manage DNS via netplan, nmcli, or resolvectl to avoid changes being overwritten.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765793663716\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"how-do-i-flush-dns-cache-on-linux\">How do I flush DNS cache on Linux?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>With systemd resolved: resolvectl flush caches. With Unbound: unbound control flush u0026lt;nameu003e or flush_zone. Applications may also cache DNS; restart services if needed.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765793678056\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003eis-bind9-the-only-option-for-authoritative-dnsu003c-strongu003e\">u003cstrongu003eIs BIND9 the only option for authoritative DNS?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>No. Alternatives include NSD, PowerDNS (authoritative), and Knot DNS. BIND9 remains common due to extensive documentation and flexibility.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765793687898\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"when-should-i-choose-managed-dns-over-self-hosting\">When should I choose managed DNS over self hosting?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>If you need global reliability, fast propagation, and minimal maintenance, managed DNS is ideal. It reduces complexity and provides SLA backed performance, something providers like YouStable bundle with hosting and 24\u00d77 support.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>DNS on a Linux server lets you resolve domain names to IPs and optionally host your own DNS zones. To [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":15520,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"iawp_total_views":109,"footnotes":""},"categories":[1134,2263,350],"tags":[],"class_list":["post-13250","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux","category-kb-domains-dns","category-knowledgebase"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/13250","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/comments?post=13250"}],"version-history":[{"count":1,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/13250\/revisions"}],"predecessor-version":[{"id":23259,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/13250\/revisions\/23259"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media\/15520"}],"wp:attachment":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media?parent=13250"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/categories?post=13250"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/tags?post=13250"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}