SOA serial mismatch between nameservers

Every zone has an SOA record containing a serial number. Secondary nameservers compare their serial with the primary’s, and fetch a fresh copy of the zone only when the primary’s is higher. If your nameservers report different serials, some of them are serving out-of-date data (RFC 1912).

Why it matters

Visitors get different answers depending on which nameserver their resolver asks. A change you made may seem to work for you and not for others, and the inconsistency can last until you notice and intervene.

Common causes

How to fix it

  1. Run DNSLint and note which servers report a different serial.
  2. Make sure each change you make to the zone increases the serial. The common convention is YYYYMMDDnn: the date plus a two-digit counter for changes that day.
  3. Check the primary allows transfers to the lagging server, and that TCP port 53 is open between them.
  4. If a serial was lowered, raise it above the highest value any secondary has seen.
  5. Ask the lagging server to refresh, or wait for the SOA refresh interval, then run the check again.

If you use a managed DNS provider, they handle transfers for you. A persistent mismatch is then worth reporting to their support.

Check your domain