Skip to main content
daily-triage/conflicting-resolver-alerts-obscure-a-stale-dns-answer.md
Daily Triage Briefing

Conflicting Resolver Alerts Obscure a Stale DNS Answer

Impact Summary

Diagnose a fictional stale DNS answer by comparing authoritative and recursive evidence, then choose containment over an unverified change. Success requires isolated validation and escalation before production action.

SeveritySEV-2
StatusResolved simulation
PlatformNetworking & DNS
Incident TypeNetworking & DNS
Published9 Sept 2026
Technologies Involved
DNS

Simulation Label

Fictional simulation. This exercise is a bounded, invented training scenario for practising operational reasoning. No real organisation, incident, telemetry, credentials or production identifiers are involved or implied.

Operational Summary

Root Cause

In the fictional reveal, one recursive path retained a stale answer while authoritative DNS and another recursive path returned the intended address.

Detection Method

Evidence-led guided investigation

Current Status

Resolved simulation

Affected Services

DNS

Incident Overview

A customer-facing hostname intermittently resolves to an old service address. One alert says the authoritative DNS answer is healthy, while another reports failures through a recursive resolver.

Application health checks aimed directly at the current service address pass. The fictional impact affects a subset of clients, so the exercise classifies it as SEV-2.The immediate objective is not to guess which alert is correct.

It is to identify where answers diverge, contain exposure without altering DNS state, and define the evidence needed before recovery. Stop and escalate if the checks cannot be run in isolation, if access would exceed read-only permissions, or if the impact expands beyond the bounded scenario.

Investigation Options

Review the available operational moves and select the best immediate action.

A

Freeze DNS changes, preserve the observations and compare the authoritative answer with each recursive path using read-only queries.

B

Edit the authoritative record again so its value is reasserted.

C

Flush every resolver cache immediately.

D

Disable DNS monitoring because the alerts conflict.

Tags:DNS