Definition · DNS & Email Spoofing
What is DNS Propagation?
“Propagation” is a misleading name for a real effect. Authoritative name servers do not push changes out to the internet; an edited record is live on the authoritative servers almost immediately. What takes time is the expiry of copies that recursive resolvers already hold. Each record is served with a TTL (time to live) in seconds, and a resolver that cached an answer keeps serving it until that timer runs out — so during the transition, different users legitimately see different answers.
What actually governs the delay
- The old record’s TTL, not the new one. A record served with a 24-hour TTL can be cached for up to 24 hours after you change it.
- Negative caching. If a name did not exist, the absence is cached too, bounded by a value in the zone’s
SOArecord. - Intermediate caches. Operating systems, browsers and application runtimes cache independently of the recursive resolver, sometimes ignoring TTLs.
- Registry and parent-zone changes. Altering the NS set or name server glue involves the registry through your registrar and has its own timings.
Planning a change
Lower the TTL well before the cutover — at least one old-TTL period ahead, so the short value is what gets cached — make the change, keep both endpoints serving until the old TTL has fully elapsed, then restore a normal TTL. Verify against the authoritative servers directly as well as through a public resolver, so you can distinguish “not changed” from “not yet expired”.
The security relevance
Propagation windows are a real overlap risk. During a migration both the old and new hosts answer, and the old one is often the less maintained of the two — a forgotten origin left running after a cutover is a classic source of shadow IT exposure and unpatched CVEs. Conversely, decommissioning the target before the record is removed creates a dangling DNS record and the subdomain takeover that follows.
Caching also shapes incident response. If an attacker achieves domain hijacking or poisons a record, reverting it does not instantly undo the damage: resolvers keep serving the malicious answer until their cached copy expires, which is one argument for keeping TTLs on critical records modest.
Related concepts
See DNS record types, passive DNS for observed historical values, and DNSSEC, where signature validity periods add a second set of expiry timers to manage.