The countdown to Elevate 2026 is on. Join us in Chicago, London, or Sydney.

Register here

Partners

Docs

LM Academy

LM Community

Platform

Solutions

Pricing

Resources

Company

Platform
  • Infrastructure
  • Cloud & Multi-Cloud
  • Log Management
  • Edwin AI
Solution
  • Automation
  • Tool Consolidation
  • Reduce MTTR
  • Cost Optimization
Industry
  • Healthcare
  • Financial Services
  • Public Sector
  • MSP
Role
  • CIO
  • ITOps
  • CloudOps
  • AIOps
There is no result.
Try it free

14-day access to the full LogicMonitor platform

Explore Platform

One platform, one system for observability, intelligence, and action.

Agentic AIOps

Infrastructure Observability

Cloud Observability

Internet Performance Monitoring

Digital Experience Monitoring

Log Management

3,000+ Integrations

Agentic AIOps Overview

Autonomously detect, diagnose, and resolve issues across your environment.

Meet Edwin AI

Turn fragmented cross-domain event noise into explainable, guided action.

AI Agent

Deploy specialized AI agents to handle investigation across the incident lifecycle.

Event Intelligence

Compress raw alert storms into high-fidelity, prioritized insights.

AI Automation

Execute governed, closed-loop remediation across automation playbooks.

ITOps Context Graph

NEW

Unify topology, telemetry, and changes into an AI-ready context layer.

MCP

NEW

Establish traceable, secure governance boundaries for AI tool integrations.

Infrastructure Observability Overview

Full visibility across your entire hybrid estate to eliminate tool sprawl.

Network Monitoring

Accelerate time to innocence with deep network path and device visibility.

Server Monitoring

Track server health, OS metrics, and resource utilization across environments.

Remote Monitoring

Monitor distributed endpoints, branch networks, and remote facility health.

VM Monitoring

Maximize hypervisor performance and streamline compute capacity planning.

SD-WAN Monitoring

Keep multi-site cloud networks connected with real-time edge visibility.

Database Monitoring

Pinpoint database query bottlenecks to keep business applications fast.

Configuration Monitoring

Minimize change failure rates by tracking device configuration drift.

Storage Monitoring

Track SAN/NAS arrays, IOPS bottlenecks, and storage capacity trends.

Cloud Observability Overview

Multi-cloud and hybrid environments unified into a single operational pane.

Container Monitoring

Automated, real-time visibility for Kubernetes and ephemeral microservices.

AWS Monitoring

Track AWS services, scaling, and costs alongside on-premises data.

Google Cloud Monitoring

Monitor native GCP infrastructure, compute, and serverless resources.

Azure Monitoring

Comprehensive visibility into Azure environments, gateways, and workloads.

AI Monitoring

Track LLM infrastructure, GPU utilization, and AI application stack health.

Oracle Cloud Monitoring

Track OCI native compute, enterprise databases, and cloud storage.

SaaS Monitoring

Validate availability and workforce productivity for critical SaaS apps.

Cloud Cost Optimization

Optimize cloud spend, maintain performance, and control budgets.

Internet Performance Monitoring Overview

Understand performance across the full stack wherever users depend on it.

Internet Health

NEW

Use global vantage points to independently validate internet outages.

Real User Monitoring

NEW

Capture actual customer journeys and frontend performance in real time.

Synthetic Monitoring

NEW

Emulate user transactions and SaaS workflows to catch problems early.

Endpoint Monitoring

NEW

Diagnose remote workforce digital experience across devices and networks.

Digital Experience Monitoring

See every dependency, regardless of ownership or location.

Website Monitoring

Protect revenue journeys with proactive synthetic checks and uptime tracking.

CDN Monitoring

NEW

Audit edge performance and latency variance across your CDN providers.

API Monitoring

NEW

Test endpoints and third-party API reliability for critical app integrations.

Application Performance Monitoring

Connect code execution and traces directly to infrastructure health.

DNS Monitoring

NEW

Speed up time-to-innocence by tracking global nameserver resolution times.

DevOps Lifecycle Monitoring

NEW

Protect release velocity by validating dependencies during deployments.

BGP Monitoring

NEW

Trace global routing changes and path leaks to secure internet reachability.

Log Management Overview

Centralize and correlate log data to resolve incidents before they escalate.

Log Analytics & Intelligence

Correlate contextual log data with metrics to speed up root-cause analysis.

WebPageTest Web Performance

Test, compare, and optimize website speed, Core Web Vitals, and performance across real devices and global locations.

Learn more
Explore Solutions

Proactively manage modern hybrid environments with predictive insights, intelligent automation, and full-stack observability.

By Business Outcome

By Role

By Industry

Professional Services

Autonomous IT

Predictive, autonomous IT built

for resilience.

Automation

Eliminate operational toil with safe, policy-governed remediation workflows.

Modernization and Transformation

Accelerate complex technology transitions while protecting core enterprise resilience.

Cloud Migration

Maintain workload performance throughout migration.

Tool Consolidation

Reduce licensing costs and silos by replacing fragmented monitoring tools.

Cost Optimization

Lower your total cost-to-serve by finding cloud waste and underused resources.

Operational Efficiency

Maximize team capacity by reducing alert storms and shift-handoff friction.

Reduce MTTR

Shorten war-rooms by surfacing topology-aware probable cause in mins.

Network Reachability

NEW

Independently audit external BGP, ISP, and SaaS provider connectivity boundaries.

Edge Deployment Optimization

NEW

Monitor SLOs, compare providers, and validate cloud and edge delivery.

Web Performance Optimization

NEW

Maximize digital checkout conversions by tracking global frontend latency metrics.

Application Resilience

NEW

Safeguard business services against transaction failures and costly downtime.

Workforce Productivity

NEW

Troubleshoot remote hardware and network issues to protect productivity.

CIO

Maximize enterprise resilience and align AI investments to measurable business ROI.

AIOps

Compress cross-domain event noise into explainable, automated ops leverage.

DevOps

Speed up releases by protecting engineering roadmaps from toil.

ITOps

Standardize incident response to reduce alert fatigue and after-hours work.

CloudOps

Unify multi-cloud visibility to optimize costs and track hybrid blast radius.

Healthcare

Protect continuity of care and EHR availability across clinical workflows.

Public Sector

Ensure mission continuity and audit readiness for citizen-facing services.

MSP

Protect service margins and scale ops using multi-tenant, AI-assisted triage.

Retail & E-commerce

Safeguard peak retail campaigns, POS uptime, and digital customer journeys.

Technology

Protect customer trust and engineering velocity with SLA-driven visibility.

Hospitality

Deliver frictionless guest experiences and keep booking engines online.

Education

Maintain always-on student portals, learning platforms, and campus networks.

Manufacturing

Prevent production downtime by unifying IT, OT-adjacent, and edge systems.

Financial Services

Secure transaction trust and meet strict resilience compliance requirements.

Why LogicMonitor?

Discover why leading IT teams trust us to unify hybrid observability and eliminate tool sprawl.

Learn more
Explore Resources

Check out our resource library for IT pros, featuring expert guides, strategies, and insights for smarter, AI-driven operations.

Resources

Upcoming Events

Platform Help

Blog

Insights and advice from the experts on all things observability and AI.

Case Studies

See what real users have to say about the LogicMonitor platform.

Webinars

Live and on-demand learning, all in one place.

IT Guides

Learn from expert guides on the topics that matter most to IT teams.

How We Compare

See how our platform stacks up against other solutions.

CONFERENCE

SWORD Day

September 17, 2026

Geneva

WEBINAR

Incident Management Has Outgrown Its Playbook

September 23, 2026

Online

View all events

Join us at innovation-focused conferences, tech talks, webinars, and other events.

Support Docs

Access product docs, release notes, and support resources.

LM Community

Join the community to learn from peers, ask questions, and connect with experts.

Customer Education

Learn more about our platform through resources and live trainings.

2026 The Year of Autonomous IT

NEW

Discover the trends, benchmarks, and strategies driving the industry shift to Autonomous IT.

Read the report
About LogicMonitor

Our observability platform proactively delivers the insights and automation CIOs need to accelerate innovation.

Leadership

Meet the leaders building the future of observability and AI.

Our Customers

See the proof of how IT teams win with LogicMonitor.

Careers

Find job openings and learn about our employee benefits.

Newsroom

Stay current with our latest mentions, press releases, and events.

Culture

NEW

Join a collaborative, values-driven culture built on innovation and growth.

Security

Purpose-built security for the hybrid observability and AI era.

Contact & Locations

Connect with our experts to explore AI-powered observability solutions.

Sustainability

Our commitment to the environment and the people in it.

The countdown to Elevate 2026 is on. Join us in Chicago, London, or Sydney.

Register here
Try it free

Platform

Explore Platform

One platform, one system for observability, intelligence, and action.

Agentic AIOps

Infrastructure Observability

Cloud Observability

Internet Performance Monitoring

Digital Experience Monitoring

Log Management

3,000+ Integrations

WebPageTest Web Performance

Test, compare, and optimize website speed, Core Web Vitals, and performance across real devices and global locations.

Solutions

Explore Solutions

Proactively manage modern hybrid environments with predictive insights, intelligent automation, and full-stack observability.

By Business Outcome

By Role

By Industry

Professional Services

Why LogicMonitor?

Discover why leading IT teams trust us to unify hybrid observability and eliminate tool sprawl.

Pricing

Resources

Explore Resources

Check out our resource library for IT pros, featuring expert guides, strategies, and insights for smarter, AI-driven operations.

Resources

Upcoming Events

Platform Help

NEW

2026 The Year of Autonomous IT

Discover the trends, benchmarks, and strategies driving the industry shift to Autonomous IT.

Company

About LogicMonitor

Our observability platform proactively delivers the insights and automation CIOs need to accelerate innovation.

Leadership

Meet the leaders building the future of observability and AI.

Careers

Find job openings and learn about our employee benefits.

Culture

NEW

Join a collaborative, values-driven culture built on innovation and growth.

Contact & Locations

Connect with our experts to explore AI-powered observability solutions.

Our Customers

See the proof of how IT teams win with LogicMonitor.

Newsroom

Stay current with our latest mentions, press releases, and events.

Security

Purpose-built security for the hybrid observability and AI era.

Sustainability

Our commitment to the environment and the people in it.

Partners

Docs

LM Academy

LM Community

Agentic AIOps

Agentic AIOps Overview

Autonomously detect, diagnose, and resolve issues across your environment.

Meet Edwin AI

Turn fragmented cross-domain event noise into explainable, guided action.

AI Agent

Deploy specialized AI agents to handle investigation across the incident lifecycle.

Event Intelligence

Compress raw alert storms into high-fidelity, prioritized insights.

AI Automation

Execute governed, closed-loop remediation across automation playbooks.

ITOps Context Graph

NEW

Unify topology, telemetry, and changes into an AI-ready context layer.

MCP

NEW

Establish traceable, secure governance boundaries for AI tool integrations.

Infrastructure Observability

Infrastructure Observability Overview

Full visibility across your entire hybrid estate to eliminate tool sprawl.

Network Monitoring

Accelerate time to innocence with deep network path and device visibility.

Server Monitoring

Track server health, OS metrics, and resource utilization across environments.

Remote Monitoring

Monitor distributed endpoints, branch networks, and remote facility health.

VM Monitoring

Maximize hypervisor performance and streamline compute capacity planning.

SD-WAN Monitoring

Keep multi-site cloud networks connected with real-time edge visibility.

Database Monitoring

Pinpoint database query bottlenecks to keep business applications fast.

Configuration Monitoring

Minimize change failure rates by tracking device configuration drift.

Storage Monitoring

Track SAN/NAS arrays, IOPS bottlenecks, and storage capacity trends.

Cloud Observability

Cloud Observability Overview

Multi-cloud and hybrid environments unified into a single operational pane.

Container Monitoring

Automated, real-time visibility for Kubernetes and ephemeral microservices.

AWS Monitoring

Track AWS services, scaling, and costs alongside on-premises data.

Google Cloud Monitoring

Monitor native GCP infrastructure, compute, and serverless resources.

Azure Monitoring

Comprehensive visibility into Azure environments, gateways, and workloads.

AI Monitoring

Track LLM infrastructure, GPU utilization, and AI application stack health.

Oracle Cloud Monitoring

Track OCI native compute, enterprise databases, and cloud storage.

SaaS Monitoring

Validate availability and workforce productivity for critical SaaS apps.

Cloud Cost Optimization

Optimize cloud spend, maintain performance, and control budgets.

Internet Performance Monitoring

Internet Performance Monitoring Overview

Understand performance across the full stack wherever users depend on it.

Internet Health

NEW

Use global vantage points for independent validation of internet outages.

Real User Monitoring

NEW

Capture actual customer journeys and frontend performance in real time.

Synthetic Monitoring

NEW

Emulate user transactions and SaaS workflows to catch problems early.

Endpoint Monitoring

NEW

Diagnose remote workforce digital experience across devices and networks.

Digital Experience Monitoring

Digital Experience Monitoring

See every dependency, regardless of ownership or location.

Website Monitoring

Protect revenue journeys with proactive synthetic checks and uptime tracking.

CDN Monitoring

NEW

Audit edge performance and latency variance across your CDN providers.

API Monitoring

NEW

Test endpoints and third-party API reliability for critical app integrations.

Application Performance Monitoring

Connect code execution and traces directly to infrastructure health.

DNS Monitoring

NEW

Speed up time to innocence by tracking global nameserver resolution times.

DevOps Lifecycle Monitoring

NEW

Protect release velocity by validating dependencies during deployments.

BGP Monitoring

NEW

Trace global routing changes and path leaks to secure internet reachability.

Logs

Log Management Overview

Centralize and correlate log data to resolve incidents before they escalate.

Log Analytics & Intelligence

Correlate contextual log data with metrics to speed up root-cause analysis.

By Business Outcome

Autonomous IT

Predictive, autonomous IT built for resilience.

Automation

Eliminate repetitive operational toil with safe, policy-governed remediation workflows.

Modernization and Transformation

Accelerate complex technology transitions while protecting core enterprise resilience.

Cloud Migration

Maintain workload performance throughout migration.

Tool Consolidation

Reduce licensing costs and data silos by replacing fragmented monitoring tools.

Cost Optimization

Lower your total cost-to-serve by finding cloud waste and underused resources.

Operational Efficiency

Maximize team capacity by reducing alert storms and shift-handoff friction.

Reduce MTTR

Shorten war-room by surfacing topology-aware probable cause in mins.

Network Reachability

NEW

Independently audit external BGP, ISP, and SaaS provider connectivity boundaries.

Edge Deployment Optimization

NEW

Monitor SLOs, compare providers, and validate cloud and edge delivery.

Web Performance Optimization

NEW

Maximize digital checkout conversions by tracking global frontend latency metrics.

Application Resilience

NEW

Safeguard business services against transaction failures and costly downtime.

Workforce Productivity

NEW

Troubleshoot remote hardware and network issues to protect productivity.

By Role

CIO

Maximize enterprise resilience and align AI investments to measurable business ROI.

AIOps

Compress cross-domain event noise into explainable, automated ops leverage.

DevOps

Speed up releases by protecting engineering roadmaps from toil.

ITOps

Standardize incident response to reduce alert fatigue and after-hours work.

CloudOps

Unify multi-cloud visibility to optimize costs and track hybrid blast radius.

By Industry

Healthcare

Protect continuity of care and EHR availability across clinical workflows.

Public Sector

Ensure mission continuity and audit readiness for citizen-facing services.

MSP

Protect service margins and scale ops using multi-tenant, AI-assisted triage.

Retail & E-commerce

Safeguard peak retail campaigns, POS uptime, and digital customer journeys.

Technology

Protect customer trust and engineering velocity with SLA-driven visibility.

Hospitality

Deliver frictionless guest experiences and keep booking engines online.

Education

Maintain always-on student portals, learning platforms, and campus networks.

Manufacturing

Prevent production downtime by unifying IT, OT-adjacent, and edge systems.

Financial Services

Secure transaction trust and meet strict operational resilience compliance requirements.

Resources

Blog

Insights and advice from the experts on all things observability and AI.

Case Studies

See what real users have to say about the LogicMonitor platform.

Webinars

Live and on-demand learning, all in one place.

IT Guides

Learn from expert guides on the topics that matter most to IT teams.

How We Compare

See how our platform stacks up against other solutions.

Upcoming Events

CONFERENCE

SWORD Day

September 17, 2026

WEBINAR

Incident Management Has Outgrown Its Playbook

September 23, 2026

View all events

Join us at innovation-focused conferences, tech talks, webinars, and other events.

Platform Help

Support Docs

Access product docs, release notes, and support resources.

LM Community

Join the community to learn from peers, ask questions, and connect with experts.

Customer Education

Learn more about our platform through resources and live trainings.

DNS MONITORING

DNS Delegation: Concepts and Best Practices

Splitting DNS zones through delegation improves performance and simplifies management. Here’s a practical breakdown of how DNS zone authority is divided and best practices for implementation.

12–18 minutes
June 3, 2026
Denton Chikura

IN THIS DEEP DIVE

CHAPTERS

    NEWSLETTER

    Subscribe to our newsletter

    Get the latest blogs, whitepapers, eGuides, and more straight into your inbox.

    SHARE

    The quick download:

    DNS delegation transfers authority for a portion of a DNS namespace to a different set of nameservers — enabling modular management, distributed responsibility, and better performance at scale.

    • DNS delegation assigns authority for a child zone to a separate set of nameservers, allowing different teams or providers to independently manage portions of the DNS namespace.

    • Glue records provide the IP addresses of delegated nameservers directly in the parent zone, preventing circular resolution dependencies that would block lookups from completing.

    • Lame delegation — where listed nameservers don’t answer authoritatively for the delegated zone — is a common source of silent DNS failures that monitoring can catch early.

    • Best practice requires at least two geographically separated authoritative nameservers per delegated zone and regular verification that NS records remain accurate and current.

    DNS delegation is a crucial aspect of managing large and complex DNS infrastructures. It allows organizations to divide their DNS zones into smaller, more manageable parts and delegate authority to different groups or individuals. Delegation is actually one of the foundations of the entire DNS system since it allows responsibility for different portions of domains to be divided, providing flexibility and other benefits. 

    In this article, we will explore the best practices for DNS delegation, including how to avoid common difficulties and ensure optimal performance and security. Whether you’re an IT professional responsible for managing a large DNS infrastructure or just curious about how DNS works, this article will provide you with valuable insights into DNS delegation and its benefits. Let’s get started!

    Summary of key DNS delegation concepts

    Here is a brief summary of what will be covered in this article.

    DNS delegation benefitsDNS delegation can improve network performance, simplify DNS management, and enable integration with third-party services.
    DNS delegation applicationsDNS delegation can be helpful when you have multiple departments or subsidiaries that require distributed responsibility, to create subdomains, to improve DNS server performance, or to use a subdomain with an external DNS provider.
    DNS zoneA DNS zone is a portion of a domain for which a DNS server is responsible for answering requests and storing DNS records.
    DNS subzoneA DNS subzone is part of a larger DNS zone that has its own set of DNS records and can be delegated to different nameservers for management.
    How DNS delegation worksDNS delegation works by assigning responsibility for a portion of a DNS namespace to a different set of DNS servers.
    Glue recordsGlue records are DNS records that provide the IP addresses of authoritative name servers for a delegated zone.
    Subzone and delegation comparisonA subzone is part of a larger DNS zone that is managed by the same DNS servers, while delegation involves assigning control of a subzone to a separate set of DNS servers.
    Lame delegationLame delegation occurs when a nameserver responsible for a delegated zone cannot provide authoritative responses to DNS queries.
    Best practices in DNS delegationUse at least two authoritative name servers, regularly monitor DNS health and configuration, and ensure that the delegated zone’s NS records are up to date and accurate.

    Definition of DNS delegation

    As you likely know, to “delegate” something means to transfer some responsibility for one or more tasks to another person or entity. The same term is used in the DNS world, where the process is called DNS zone delegation (or sometimes simply DNS delegation). 

    DNS delegation is the process by which a parent DNS zone indicates to DNS resolvers that it has delegated the authority for a DNS subzone (or child zone) to a different set of DNS servers. This allows the DNS resolvers to locate and query the delegated DNS servers for the subzone’s DNS records.

    DNS delegation benefits

    Using DNS delegation can provide a number of advantages to a DNS administrator and the organization as a whole:

    • Improved performance: By delegating a portion of your DNS namespace to a different set of DNS servers, you can improve performance by reducing the load on your primary DNS servers.
    • Simplified DNS management: DNS delegation can simplify DNS management by allowing different teams or locations to manage their own DNS configurations.
    • Integration with third-party services: DNS delegation allows you to integrate with third-party services, such as content delivery networks (CDNs), cloud-based email services, or tracking services, that require you to delegate DNS management for a portion of your DNS namespace to their own DNS servers.

    DNS delegation applications

    The various benefits of DNS delegation described above apply to many uses of DNS. However, they dictate a number of situations where DNS delegation can be especially useful. 

    Common DNS delegation applications include situations where the following are needed:

    • Distribution of responsibility: You have multiple departments or subsidiaries and need to delegate responsibility for DNS management to different teams or locations.
    • Subdomain specialization: You want to create a subdomain for a website or web application that requires separate DNS management or would benefit from it.
    • Performance enhancement: You want to take advantage of load distribution and geographic distribution to optimize DNS query responses. By delegating subzones to different DNS servers, organizations can efficiently distribute query load. In addition, strategically delegating to DNS servers in different geographic locations ensures that users receive faster DNS responses by connecting to the servers closest to their location. By incorporating these techniques, organizations can enhance performance, optimize resource utilization, and provide a faster and more efficient DNS resolution experience for their users. 
    • Subdomain outsourcing: You may need to use a subdomain for a specific purpose that involves external management. For example, many organizations create a separate subdomain specifically for email marketing purposes and delegate it to a specialized email service company that handles the technical aspects of email authentication and sender reputation.

    Understanding zones and subzones

    DNS organizes authoritative information into units called zones. A zone is essentially a portion of the DNS namespace for which a particular DNS server is authoritative. Each zone contains a set of resource records that define the DNS information for that zone.

    Zones are distributed to both primary (main) and secondary (backup) name servers, which respond with authoritative answers for those zones. The purpose of distributing zones to multiple servers is to ensure redundancy and availability in case one or more servers become unavailable.

    There are two types of zones: forward-mapping and reverse-mapping. Forward-mapping zones are used to map hostnames to IP addresses, while reverse-mapping zones are used to map IP addresses to hostnames. Both types of zones include the same basic set of information:

    • Zone name
    • Start Of Authority (SOA) record
    • NameServer (NS) records
    • Other resource records (optional)

    The image below shows an example of a BIND format forward mapping zone.n essential part of DNS monitoring. Key considerations in this area include geo-based DNS routing, watching DNS latency, and monitoring DNS servers.tation for robust API development. A well-crafted API architecture in an evolving digital landscape remains pivotal, enabling efficient communication and collaboration between systems.

    BIND forward mapping zone

    A subzone, also referred to as a child zone, is a division of a zone that shares the latter parts of the domain name with the parent. For instance, if the parent domain name is company.com, a subzone could be sales.company.com, as shown below. Like a zone, a subzone is a group of DNS records that are managed together for administrative convenience. Typically, subzones are created to meet specific organizational requirements, such as separating different departments or regions within a company.

    While the terms “subzone” and “delegated zone” may cause some confusion, it’s important to note that a delegated zone is essentially a subzone, but with the difference that the delegated zone is managed on separate DNS servers from the parent zone, unlike a subzone. We will have a whole section comparing these two concepts later in this article.

    A zone and a subzone

    How DNS delegation works

    DNS was designed over three decades ago. It has scaled well even as the size of the Internet has dramatically increased and DNS management requirements have increased with it specifically because delegation essentially decentralizes management. Let’s take a look at how delegation works in detail using the example outlined above.

    In the previous subzone example, the DNS administrator of company.com is still responsible for the subzone. However, let’s say that the sales department has specific needs and no longer wants to follow the rules of the DNS administrator of company.com; it wants to set up its own DNS servers and manage sales.company.com with its own parameters. The sales department then needs to work with the DNS administrator of company.com to set up delegation, so the authority for sales.company.com is delegated to a new set of DNS servers managed by the sales department.
    Effective delegation involves close collaboration between the parent and child zones. Specifically, the parent zone must include NS records for the child’s new authoritative servers (primary and secondary) to refer to other recursive resolvers, as shown in the following figure. These are called glue records and are explained further below.

    Delegation example showing glue records connecting the parent zone to the delegated zone

    Actually, DNS delegation is happening all the time because it all begins from the very base: the root domain. Delegation in DNS happens hierarchically, from the root domain down to the domain name in question. Here is an overview of how delegation happens when you query a domain name, let’s say www.example.com.

    When the DNS resolver (typically at your ISP) receives the DNS query from the client, it checks in its cache. If it does not have the IP address it needs in the cache and does not have any forwarding configuration, by default, it sends an iterative query to the root name servers. The root name server’s IP addresses (both IPv4 and IPv6) are stored in a file known as “root hints,” which is part of any recursive resolver.
    The root server answers with a referral, since it is authoritative for part of the requested fully qualified domain name (FQDN) — only the very last part of the name, which in this case is .com. It includes the NS records for the delegated domain. For instance, if the requested domain is www.example.com, the root server would provide a list of .com name servers, since that’s the highest level, as shown below.

    com.			172800	IN	NS	a.gtld-servers.net.
    com.			172800	IN	NS	b.gtld-servers.net.
    com.			172800	IN	NS	c.gtld-servers.net.
    com.			172800	IN	NS	d.gtld-servers.net.
    com.			172800	IN	NS	e.gtld-servers.net.
    com.			172800	IN	NS	f.gtld-servers.net.
    com.			172800	IN	NS	g.gtld-servers.net.
    com.			172800	IN	NS	h.gtld-servers.net.
    com.			172800	IN	NS	i.gtld-servers.net.
    com.			172800	IN	NS	j.gtld-servers.net.
    com.			172800	IN	NS	k.gtld-servers.net.
    com.			172800	IN	NS	l.gtld-servers.net.
    com.			172800	IN	NS	m.gtld-servers.net.

    After receiving a referral message from a root server with a list of .com name servers, the recursive resolver caches the information. Then it chooses a name server from the list and sends it an iterative query.

    The delegated domain’s name server responds with a referral since it is authoritative for part of the requested domain. In the referral message, it sends the NS records for the delegated domain. If the requested FQDN is www.example.com, the .com server would respond with a list of example.com name servers.

    example.com.		172800	IN	NS	a.iana-servers.net.
    example.com.		172800	IN	NS	b.iana-servers.net.

    After caching the answers from the previous step, the recursive resolver continues the process, sending an iterative query for the FQDN to a chosen name server (e.g., a.iana-servers.net). Once the example.com name servers are reached, the authoritative name server sends an Authoritative Answer (AA) field-set answer back to the resolver, including valid responses such as NXDOMAIN, or in the case of this example, the A record.

    www.example.com.		86400 	IN	A	93.184.216.34

    The image below illustrates the process described above, showing a DNS resolution trace from root DNS servers down to the example.com domain authority. You can find the tool used for this here.

    DNS resolution trace from root zone down to example.com

    Glue records

    Glue records are essential to delegation as they provide (in the form of A and AAAA records) information to connect the parent domain to the child domain. They are used to help resolve circular dependencies between domain names and their corresponding name servers. 
    Let’s look at the delegation example again. The parent zone company.com is delegating sales.company.com to the ns1.sales.company.com and ns2.sales.company.com name servers. Now, since we are using name servers that are a child of the zone it’s being applied to (e.g. ns1.sales.company.com is a child of sales.company.com), we need to use glue records to know where these name servers are (by their corresponding IP addresses). Otherwise, it will get stuck in a resolution loop. So, the parent zone (company.com) includes not just the delegation (NS records) but also includes the A (AAAA if needed) records that map (or glue) the nameserver’s names to their IP addresses.

    Example use of glue records
    sales.company.com. IN NS ns1.sales.company.com.
    sales.company.com. IN NS ns2.sales.company.com.
    ns1.sales.company.com. IN A 2.2.2.2
    ns2.sales.company.com. IN A 3.3.3.3

    Subzone and delegation comparison

    As the administrator of a parent zone, it’s important to consider the appropriate use of subzones and delegation. To maintain control over a child zone and store its data on the same servers as the parent zone, subzones are the way to go. However, if you want the child zone to have its own administrative control and store its data on separate servers, delegation is the better option.

    In internal-only domain configurations, delegation is rarely necessary, while subzones are much more commonly used.

    DNS subzoneDNS delegation
    Administrative controlParent maintains control over the childChild maintains its own administrative control
    Hosting dataChild data is hosted on the same servers as parent zone dataChild data is hosted on a separate set of servers
    CoordinationSimple and easy to implement because it’s under the same administrationRequires good coordination between parent and child administrators
    Common UsageUsed more for internal-only domainsUsed for larger networks or external domains
    SetupEasy to set up and manageMore complex and requires technical expertise

    Lame delegation

    Lame delegation refers to a problematic situation where the parent domain attempts to delegate a child domain to a specific set of name servers that are either not authoritative for the zone or not operational with DNS services. Let’s take a look at these common scenarios of lame delegation. You can also find technical definitions in RFC 8499 and RFC 1912.

    The image below illustrates a scenario where the parent zone (company.com) responds with a referral that includes incorrect glue records pointing the recursive resolver to an incorrect or unreachable IP address. When the recursive DNS follows this referral, it turns out that it cannot resolve the domain name since the IP addresses are unreachable (servers down) or are available but are not running any DNS service (timeout). The client would likely experience some delay and eventually receive a “SERVFAIL” response code from the recursive DNS resolver.

    Lame delegation scenario

    Imagine now (as shown in the image below) that the recursive resolver receives a referral from the parent zone where just one of the name servers is correct. Server 2.6.6.6 is not authoritative for sales.company.com, and every time the resolver queries the name server 2.6.6.6 for an authoritative answer, it won’t get any response and will start over again from the root servers. In this example, the recursive resolver has a 50% probability (assuming that it uses a round-robin mechanism) of selecting the correct name server with IP address 2.2.2.2, as there are two NS records provided by the parent zone. To end-users, the issue may appear as slow name resolution, as the recursive resolver continues to loop around repeatedly until it reaches the final authoritative name server at 2.2.2.2, or until a timeout occurs.

    Lame delegation scenario

    In conclusion, lame delegations can cause DNS resolution errors and slow down the process of resolving domain names, as queries for the delegated subdomain are repeatedly referred to the lame DNS server. They can be identified by analyzing DNS query logs. Lame delegation can be resolved by correcting the configuration of the DNS server and keeping it updated or by delegating the subdomain to a different DNS server that is able to provide valid responses. 

    Best practices in DNS delegation 

    Effective delegation of DNS zones is crucial for maintaining a reliable and highly available DNS infrastructure. When delegation is done properly, it allows for efficient resolution of DNS queries and minimizes the risk of issues. In this section, we will discuss some best practices to follow when delegating DNS zones to ensure optimal performance and security of your DNS infrastructure.

    • Maintain accuracy: Ensure that the delegated zone’s NS records are up to date and accurately reflect the current set of authoritative name servers. By doing this, you can avoid lame delegation issues. This can be achieved by regularly monitoring the status of the delegated name servers, ensuring that they are properly configured and functioning correctly.
    • Use at least two authoritative name servers: Delegating a domain to only one name server can lead to single points of failure, which can cause downtime for the domain. To ensure that your domain remains available, it is recommended to use at least two name servers that are located in different geographic regions.
    • Prioritize communication and documentation: Clear communication among all the parties involved is essential for effective DNS delegation. Ensure that everyone understands their roles and responsibilities, and create thorough documentation that provides a record of what has been delegated and who is responsible for each part of the process.
    • Regularly monitor DNS health and configuration: Monitor your DNS servers and zone files frequently to ensure that they are performing optimally and are free from errors. Use DNS monitoring tools to detect issues before they become critical and impact your online services.

    Summary of key concepts

    DNS delegation is a fundamental part of the Internet that allows it to be efficiently maintained despite its huge size and complexity. When organizations delegate DNS responsibilities to different teams or locations, they can simplify DNS management, enhance performance, and incorporate third-party services. However, to ensure the safety and reliability of DNS infrastructure, it’s important to use best practices such as those outlined in this article. By implementing DNS delegation correctly, organizations can ensure efficient DNS management and minimize potential DNS infrastructure problems.

    Stop guessing about DNS performance. Start knowing.

    LogicMonitor continuously monitors your DNS infrastructure from multiple global vantage points, giving you the resolution-time data and availability insights you need to optimize confidently.

    Get a Demo

    FAQs

    What is DNS delegation?

    DNS delegation is the process where a parent DNS zone designates a separate set of nameservers as authoritative for a child zone (subzone). This lets different teams, organizations, or providers independently manage portions of the DNS namespace without requiring access to the parent zone.

    What are glue records and why are they necessary?

    Glue records are A or AAAA records placed in a parent zone to specify the IP addresses of delegated nameservers. They prevent circular resolution: if a nameserver’s hostname falls within the zone it’s authoritative for, resolvers need those IP addresses upfront to initiate the delegation chain.

    What causes lame delegation and how do you fix it?

    Lame delegation happens when a nameserver listed in NS records for a zone doesn’t actually hold authoritative data for that zone — often due to misconfiguration, expired hosting, or a server going offline. Fix it by ensuring NS records accurately reflect active, properly configured nameservers, and monitor for lame delegation continuously.

    What are the main use cases for DNS delegation?

    DNS delegation is used to let departments or subsidiaries manage their own DNS subdomains, to integrate with third-party services like CDNs or cloud providers that require delegated control, to create specialized subdomains for applications, and to distribute DNS management load across geographically distributed teams.

    By Denton Chikura

    Technical Writer

    Denton Chikura is a technical writer and longtime observability advocate focused on helping site reliability engineers and engineering teams discover the tools and capabilities that strengthen internet resilience. He works at the intersection of monitoring, performance, and infrastructure to make complex systems more understandable and usable, bridging the gap between deep technical detail and real‑world operations. His goal is to help teams build faster, detect issues earlier, and recover smarter, ultimately making the internet a better, more reliable place for everyone.

    Disclaimer: The views expressed on this blog are those of the author and do not necessarily reflect the views of LogicMonitor or its affiliates.

    © LogicMonitor 2026 | All rights reserved. | All trademarks, trade names, service marks, and logos referenced herein belong to their respective companies.

    Product

    Platform

    Infrastructure

    Cloud & Multi-Cloud

    Log Management

    Edwin AI

    Enterprise

    Demo

    Pricing

    WebPageTest Pricing

    RUM Monitoring

    IPM Monitoring

    Synthetic Monitoring

    How We Compare

    Datadog

    Dynatrace

    Virtana

    Solarwinds

    PRTG

    ManageEngine

    ScienceLogic

    SiteScope

    BigPanda

    About

    Careers

    Our Partners

    Leadership

    Newsroom

    Security

    AI Governance

    Sustainability

    Legal

    Documentation

    Docs Hub

    Release Notes

    Security

    Support Center

    Resources

    Autonomous IT in 2026

    Resource Library

    LM Academy

    Blog

    Case Studies

    Customer Education

    Connect

    Contact & Locations

    Submit a Ticket

    Events

    LM Community

    Careers


    Product

    Platform

    Infrastructure

    Cloud & Multi-Cloud

    Log Management

    Edwin AI

    Enterprise

    Demo

    Pricing

    WebPageTest Pricing

    RUM Monitoring

    IPM Monitoring

    Synthetic Monitoring


    How We Compare

    Datadog

    Dynatrace

    Virtana

    Zenoss

    Solarwinds

    PRTG

    ManageEngine

    ScienceLogic

    SiteScope

    BigPanda


    About

    Careers

    Our Partners

    Leadership

    Newsroom

    Security

    AI Governance

    Sustainability

    Legal


    Documentation

    Docs Hub

    Release Notes

    Security

    Support Center


    Resources

    Autonomous IT in 2026

    Resource Library

    LM Academy

    Blog

    Case Studies

    Customer Education


    Connect

    Contact & Locations

    Submit a Ticket

    Events

    LM Community

    Careers


    Privacy Policy

    Terms of Use

    Preference Center

    Do Not Sell My Information

    © 2026 LogicMonitor