Incident Overview
Fictional company Meridian Retail Group runs an internal service at api.internal.corp, authoritative on primary name server ns1.internal.corp (10.0.4.10) with secondary ns2.internal.corp (10.0.4.11). After migrating the backend to a new address, the platform team updated the primary zone.
Within an hour, some app servers connect successfully while others intermittently receive HTTP 502 errors from a backend that no longer exists.
Investigation Options
Review the available operational moves and select the best immediate action.
Restart the affected application servers to clear cached connections and stateful sessions blamed for the 502 errors.
Correct the TSIG key mismatch on the secondary name server, then force a fresh AXFR zone transfer and confirm SOA serial parity across all authoritative servers.
Manually edit the zone file directly on the secondary name server to insert the new record while the transfer failure is investigated.
Reduce the DNS TTL on the affected record globally to accelerate propagation across all resolvers.