You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerDNS权威服务器配置NXDomain请求转发至外部DNS的问题

PowerDNS权威服务器配置NXDomain请求转发至外部DNS的问题

Hey there! Let's clear this up for you—you're right that the PowerDNS Authoritative Server on its own can't handle forwarding requests (whether they result in NXDomain or are for domains you don't control) to external DNS like Google's 8.8.8.8. The PowerDNS Recursor is indeed the tool you need here, and it's way simpler to set up than you might think. Let's walk through it step by step:

1. 先安装PowerDNS Recursor

First, grab the Recursor package (the command depends on your OS):

  • Debian/Ubuntu 系:apt install pdns-recursor
  • RHEL/CentOS 系:yum install pdns-recursor

2. 配置Recursor处理转发

Open up the Recursor's config file (usually /etc/powerdns/recursor.conf):

  • Add a forward-zones line to send all non-authoritative queries to Google DNS:
    forward-zones=.=8.8.8.8;8.8.4.4
    
    The . here is a catch-all, meaning any query the Recursor can't answer on its own gets sent to Google's servers. If you ever wanted to forward only specific domains later, you'd replace . with something like example.com.
  • Make sure allow-from is set to let your authoritative server connect to the Recursor (if they're on the same machine, include 127.0.0.1):
    allow-from=127.0.0.1,你的权威服务器IP地址
    
  • Restart the Recursor service to apply changes: systemctl restart pdns-recursor

3. 让权威服务器对接Recursor

Now head over to your PowerDNS Authoritative Server's config file (typically /etc/powerdns/pdns.conf):

  • Add the forward-zones-recurse setting to tell the authoritative server to send queries for non-controlled domains to the Recursor:
    forward-zones-recurse=.=127.0.0.1:53
    
    (If your Recursor is on a different server, replace 127.0.0.1 with its IP.)
  • Restart the authoritative server: systemctl restart pdns

4. 验证配置是否生效

Test it by querying a domain you don't manage (like google.com) against your authoritative server:

dig @你的权威服务器IP google.com

You should get a valid response from Google DNS, routed through your Recursor and authoritative server.

小澄清:关于真正的权威NXDomain

If you're thinking about domains your server does control—like if someone asks for fake.yourdomain.com which doesn't exist—your authoritative server will correctly return NXDomain, and you shouldn't forward that. Your server is the source of truth for your domains, so forwarding those would defeat the purpose of running an authoritative server. It sounds like you probably meant non-authoritative queries that were returning NXDomain, which the setup above fixes perfectly.

备注:内容来源于stack exchange,提问作者Fang

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.17 12:15:32