Glue records explained
Suppose example.com uses the nameservers ns1.example.com and ns2.example.com. To look up ns1.example.com, a resolver must first ask example.com’s nameservers, which it can’t find without already knowing ns1.example.com. Glue records break that loop. They are address records for the nameservers, published by the parent zone (for example .com) alongside the delegation.
Why it matters
Without glue, a domain whose nameservers sit inside itself cannot be resolved at all. Wrong glue is nearly as bad: if the addresses at the parent are out of date, resolvers are sent to servers that no longer answer, and lookups fail or slow down even though your own zone is correct.
When you need them
- Glue is needed when a nameserver’s name is inside the domain it serves, such as
ns1.example.comforexample.com. - It is not needed when the nameservers belong to another domain, such as
ns1.dnshost.net.
Common causes of problems
- The nameserver host records were never registered at your registrar.
- A nameserver changed IP address and the glue at the registrar was not updated.
- The glue has an A record but no AAAA record, or the reverse, and the two disagree with your zone.
How to fix it
- Run DNSLint and read what it reports for glue and nameserver address records.
- At your registrar, find the section for registering or editing nameserver (host) records.
- Make sure every nameserver inside your own domain has its current IPv4 and IPv6 addresses listed.
- Make sure those addresses match the A and AAAA records inside your zone.
- Run the check again once the registry has updated.