Definition · Subdomain Enumeration
What is NS Record?
NS (name server) records are how DNS delegation works. The root zone’s NS records point at the servers for .com; the .com zone’s NS records for example.com point at whichever name servers the domain owner nominated; and the example.com zone repeats those names at its own apex. A resolver walks that chain downwards until it reaches a server that answers authoritatively.
example.com. NS ns1.provider.net.
example.com. NS ns2.provider.net.
internal.example.com. NS ns1.another-provider.net.
The second block is a sub-delegation: everything under internal.example.com is handed to a different set of servers, which may be operated by a different team or supplier entirely.
Glue, lame delegations and mismatches
If the nominated name servers live inside the zone being delegated, the parent must also publish their addresses as glue records, otherwise resolution deadlocks. Two failure modes are worth knowing:
- Lame delegation — a server named in an NS record does not answer authoritatively for the zone, so a share of queries fail or fall back slowly to the remaining servers.
- Parent/child mismatch — the NS set at the parent differs from the set published in the zone itself, usually after a migration where only one side was updated.
Why stale NS records are a security problem
A delegation you no longer control is a takeover route. If internal.example.com is delegated to a DNS provider account that has since been closed, whoever recreates that zone on the same provider becomes authoritative for the whole subtree — able to publish any record beneath it, including hostnames that pass HTTP domain validation and yield a TLS certificate. This is the delegation form of subdomain takeover, and it is a dangling DNS record in the same sense as an orphaned CNAME, with a wider blast radius.
NS records are also a reconnaissance signal. They identify the DNS providers in use, and sub-delegations frequently expose internal naming conventions and business units that would otherwise need guessing during subdomain enumeration. SurfaceLoop monitors for dangling delegations and CNAME references as part of continuous subdomain monitoring.
Related concepts
See DNS record types, DNS zone transfer, DNSSEC (where a DS record in the parent accompanies the delegation), and domain hijacking for what happens when the NS set is changed by someone else.