<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DNS | WebPixie Blog</title><description>Posts tagged with DNS on the WebPixie Blog.</description><link>https://webpixie.io/blog/</link><language>en-gb</language><atom:link href="https://webpixie.io/blog/tag/dns/rss.xml" rel="self" type="application/rss+xml"/><item><title>Namecheap&apos;s outage didn&apos;t break DNS resolution. It broke DNS management.</title><link>https://webpixie.io/blog/post/namecheap-outage-dns-resolution-vs-management</link><guid isPermaLink="true">https://webpixie.io/blog/post/namecheap-outage-dns-resolution-vs-management</guid><description>During Namecheap&apos;s 13 Aug 2026 outage, DNS zone resolution stayed up while DNS management went down. A real, confirmed case for why resolution and management are separate failure domains.</description><pubDate>Thu, 10 Sep 2026 18:19:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/09/namecheap-outage-dns-resolution-vs-management-feature.png" medium="image"/><category>DNS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>IPv6 and dual-stack sites: what changes for uptime and DNS monitoring</title><link>https://webpixie.io/blog/post/ipv6-dual-stack-monitoring</link><guid isPermaLink="true">https://webpixie.io/blog/post/ipv6-dual-stack-monitoring</guid><description>A broken IPv6 path does not take a dual-stack site down. It adds real, measurable delay for a share of visitors while an IPv4-only uptime check keeps reporting &quot;up&quot; the entire time.</description><pubDate>Wed, 09 Sep 2026 11:25:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/09/ipv6-dual-stack-monitoring-feature.png" medium="image"/><category>DNS</category><category>Uptime Monitoring</category><author>Matt Scott</author></item><item><title>CNAME at the apex: ALIAS vs ANAME vs CNAME flattening</title><link>https://webpixie.io/blog/post/cname-apex-alias-aname-flattening</link><guid isPermaLink="true">https://webpixie.io/blog/post/cname-apex-alias-aname-flattening</guid><description>A real CNAME can never sit at a zone apex, so every provider invented its own workaround: ALIAS, ANAME, CNAME flattening. Three names for roughly the same trick, with real differences in TTL handling and DNSSEC behavior, plus a newer standards-based alternative most guides skip.</description><pubDate>Thu, 03 Sep 2026 15:21:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/09/cname-apex-alias-aname-flattening-feature.png" medium="image"/><category>DNS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>SERVFAIL: diagnosing DNSSEC validation failures</title><link>https://webpixie.io/blog/post/servfail-dnssec-validation-failures</link><guid isPermaLink="true">https://webpixie.io/blog/post/servfail-dnssec-validation-failures</guid><description>DNSSEC fails closed: a broken chain of trust returns SERVFAIL, not a wrong answer. Two real incidents, Slack in 2021 and a TLD-wide DENIC outage in 2026, show the two root causes that actually happen, and the fast path to telling them apart.</description><pubDate>Fri, 28 Aug 2026 12:34:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/09/servfail-dnssec-validation-failures-feature-1.png" medium="image"/><category>DNS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>Subdomain takeover is an ops problem too</title><link>https://webpixie.io/blog/post/subdomain-takeover-ops-problem</link><guid isPermaLink="true">https://webpixie.io/blog/post/subdomain-takeover-ops-problem</guid><description>Every subdomain takeover guide is written for a security team hunting exposure. Most takeovers start as an ops mistake: a CNAME left behind after a vendor migration or a decommissioned SaaS tool, with nobody deleting the record.</description><pubDate>Sat, 15 Aug 2026 13:51:47 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/08/subdomain-takeover-ops-problem-feature.png" medium="image"/><category>DNS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>DNS propagation is a myth</title><link>https://webpixie.io/blog/post/dns-propagation-myth</link><guid isPermaLink="true">https://webpixie.io/blog/post/dns-propagation-myth</guid><description>DNS propagation isn&apos;t a transport mechanism, it&apos;s cache expiry. Negative caching, not TTL alone, explains why a fresh record can lag. Here&apos;s how to actually verify a change, and why that verification never really stops.</description><pubDate>Wed, 05 Aug 2026 10:37:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/08/dns-propagation-myth-feature-1.png" medium="image"/><category>DNS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>DNS-AID explained: what it is and why it isn&apos;t settled yet</title><link>https://webpixie.io/blog/post/dns-aid-explained</link><guid isPermaLink="true">https://webpixie.io/blog/post/dns-aid-explained</guid><description>DNS-AID proposes publishing AI agents through DNS records instead of well-known URIs. Here is what the draft actually specifies, what the Linux Foundation launch means, and why the record shape is still inconsistent across every implementation we checked.</description><pubDate>Thu, 02 Jul 2026 10:08:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/07/dns-aid-explained.png" medium="image"/><category>DNS</category><category>AI Crawlers</category><author>Matt Scott</author></item><item><title>Domain monitoring vs DNS monitoring: what each catches</title><link>https://webpixie.io/blog/post/domain-vs-dns-monitoring</link><guid isPermaLink="true">https://webpixie.io/blog/post/domain-vs-dns-monitoring</guid><description>Domain monitoring and DNS monitoring watch two different layers of the same name: registration versus resolution. Here is what each one catches, where they overlap at the nameserver, and which layer catches which outage, so you know why you need both.</description><pubDate>Sun, 28 Jun 2026 12:46:31 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/07/domain-and-dns-compared.png" medium="image"/><category>Domain</category><category>DNS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>How to detect DNS record changes</title><link>https://webpixie.io/blog/post/detect-dns-record-changes</link><guid isPermaLink="true">https://webpixie.io/blog/post/detect-dns-record-changes</guid><description>Detecting DNS record changes is a snapshot-and-diff loop on top of dig and the SOA serial. The hard part is not the detection, it is filtering the false positives from GeoDNS, round-robin, and CDN IP rotation so you only alert on changes that matter.</description><pubDate>Tue, 23 Jun 2026 11:36:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/07/detecting-dns-changes.png" medium="image"/><category>DNS</category><category>Monitoring</category><author>Matt Scott</author></item><item><title>What DNS monitoring catches (and what it can&apos;t)</title><link>https://webpixie.io/blog/post/what-dns-monitoring-catches</link><guid isPermaLink="true">https://webpixie.io/blog/post/what-dns-monitoring-catches</guid><description>DNS monitoring catches the silent failures an uptime check never shows: records pointing at the wrong server, nameservers out of sync, expired DNSSEC signatures, broken email records. Here is exactly what it catches, what it cannot, and how to start with dig.</description><pubDate>Thu, 18 Jun 2026 11:34:00 GMT</pubDate><media:content url="https://static.cdn.webpixie.io/blog/2026/07/inside-your-dns-traffic.png" medium="image"/><category>DNS</category><category>Monitoring</category><author>Matt Scott</author></item></channel></rss>