
If you want to run your own nameservers under a domain you own — for example ns1.yourdomain.com — you will encounter a classic chicken-and-egg problem. To resolve yourdomain.com, the resolver needs the IP of ns1.yourdomain.com. But ns1.yourdomain.com is under the very domain being resolved. Glue Records exist specifically to break this circular dependency.
What is a Glue Record?
A Glue Record is an A (or AAAA) record stored directly at the registrar or in the parent zone, rather than in the domain's own zone file. This allows resolvers to learn the IP address of a nameserver before they can successfully resolve the domain that nameserver belongs to, breaking the circular dependency.
Glue Records are sometimes called "Child Name Server" records or "in-bailiwick NS" records because the nameserver subdomain resides within (in the bailiwick of) the same domain.
Why Are Glue Records Needed?
Suppose you want yourdomain.com to use nameservers named ns1.yourdomain.com and ns2.yourdomain.com — either for branding or to self-host DNS on your own VPS:
- A resolver asks the registry what nameservers serve
yourdomain.com - The registry answers:
ns1.yourdomain.comandns2.yourdomain.com - The resolver needs the IP of
ns1.yourdomain.com— but that hostname is underyourdomain.com, which cannot be resolved yet! - Circular dependency — resolution fails entirely
Glue Records solve this by having the registry store the IP addresses of ns1 and ns2 directly in its own database. When the resolver asks for the nameservers, the registry returns both the hostname and the IP address together.
How to Set Up Glue Records
Step 1 — Configure DNS Server Software on Your Server
First, install DNS server software on your VPS such as BIND, PowerDNS, or Knot DNS, and configure a zone file for your domain.
Step 2 — Register Child Nameservers at Your Registrar
Log in to your domain management panel at your registrar (such as AsiaGB) and find the "Child Name Server" or "Host Records" section. Enter:
- Hostname:
ns1(without the.yourdomain.comsuffix) - IP Address: your server's IP, e.g.,
203.0.113.10
Repeat for ns2 with a different IP address. Having at least two nameservers is strongly recommended for redundancy.
Step 3 — Point the Domain's NS to ns1.yourdomain.com
After the Glue Records are saved, update the domain's nameservers to ns1.yourdomain.com and ns2.yourdomain.com. Allow 24–48 hours for full DNS propagation.
Note: Glue Records are only required when the nameserver hostname is a subdomain of the domain being served (in-bailiwick). If you use nameservers from another provider such as ns1.someotherprovider.com, no Glue Record is needed because someotherprovider.com can be resolved independently.
Real-World Use Cases for Glue Records
- Web Hosting Providers — Providers like AsiaGB use Glue Records so customers can point NS to ns1.asiagb.com and ns2.asiagb.com
- White-label DNS — Resellers who want branded nameservers such as ns1.yourbrand.com
- Self-hosted DNS — Developers or SysAdmins running BIND on their own VPS
- Anycast DNS — Large DNS providers with globally distributed nodes
Verifying Your Glue Record
Use this command to confirm the Glue Record has been registered correctly:
dig +additional NS yourdomain.com @a.iana-servers.net
The Additional Section of the output should show the IP addresses of ns1 and ns2 alongside the NS records.
Glue Records and DNSSEC — What You Need to Know
If your domain uses DNSSEC (Domain Name System Security Extensions), there are additional considerations when setting up in-bailiwick Glue Records. DNSSEC relies on a Chain of Trust that begins at the Root Zone and extends down to your domain. When you run your own nameservers, you become a link in that chain and must manage it correctly.
Key steps when combining Glue Records with DNSSEC:
- DS Record (Delegation Signer) — You must submit your DNSSEC signing key's DS record to the registrar so the parent zone can sign the delegation and complete the Chain of Trust.
- DNSKEY in the Zone file — The zone served by your nameserver must contain a DNSKEY record that matches the DS record filed with the registrar.
- Key Rollover timing — When rotating DNSSEC keys, update the DS record at the registrar before the old key expires. Failure to do so causes SERVFAIL for resolvers with DNSSEC validation enabled.
If your use case does not demand this level of security management, using your registrar's or hosting provider's nameservers (such as those from AsiaGB) offloads DNSSEC handling automatically.
Common Mistakes When Configuring Glue Records
Despite being conceptually straightforward, Glue Records are a common source of misconfiguration. Here are the most frequently encountered errors and how to avoid them:
| Mistake | Effect | Fix |
|---|---|---|
| Missing A record in the zone file | Resolver gets the Glue IP but cannot connect to the NS | Add an A record for ns1/ns2 inside your zone file as well |
| Glue IP does not match the actual DNS server | Every query times out | Update the Glue Record at the registrar whenever you move the server |
| Only one nameserver registered | Any outage takes the domain completely offline | Always register at least two NS records on separate IPs or networks |
| Switching NS before Glue propagates | Domain fails to resolve for 24–48 hours | Verify the Glue Record with dig first, then point the domain's NS |
Glue Records and Anycast DNS — Advanced Architecture
Large DNS operators combine Glue Records with Anycast routing to serve the same nameserver IP from multiple nodes worldwide. BGP routing directs each query to the nearest available node, reducing latency without changing the IP registered in the Glue Record.
A simplified Anycast DNS topology:
- Nodes in Bangkok, Singapore, and Tokyo — all announcing the same IP, e.g.
192.0.2.53 - The Glue Record at the registrar records
192.0.2.53forns1.yourdomain.com - A user in Thailand reaches the Bangkok node — sub-5ms latency
- A user in Japan reaches the Tokyo node — similarly low latency
This architecture is worthwhile when you need global DNS latency below 20ms. For typical websites, two Glue Records pointing to two VPS instances in separate data centers provide sufficient redundancy without the complexity of Anycast.
How TTL Affects Glue Record Changes
Time To Live (TTL) determines how long resolvers cache a DNS response. When you need to change a Glue Record — for example, moving to a new server IP — TTL governs how long the old value will be served from caches around the world.
Best practices for managing TTL around Glue Record changes:
- Lower the TTL in advance — At least 48 hours before a planned IP change, reduce the existing record's TTL to 300 seconds (5 minutes). This shortens the propagation window once you make the actual change.
- Make the change, then wait — After updating the Glue IP at your registrar, wait one full original-TTL period before decommissioning the old server to serve any stragglers hitting the cached IP.
- Raise TTL again afterward — Once the change has fully propagated, raise the TTL back to 3600 or higher to reduce query load on your nameservers.
Note that Glue Record TTL is controlled by the registry, not your zone file. Check your registrar's documentation for the default TTL they apply, as it often ranges from 172800 seconds (48 hours) to 86400 seconds (24 hours).
Register a Domain with Custom Nameserver Support
AsiaGB supports Child Nameserver (Glue Record) configuration for all domains registered through us. Register a .com domain for just 500 THB/year.
Register a Domain