XiaTools

Troubleshooting Domain Resolution Failures Caused by Expired SOA Timers

Updated 10 Oct 2026

Domain resolution failures can often be traced back to stale or incorrectly configured Start of Authority (SOA) parameters, specifically when secondary name servers fail to refresh zone data within the designated window. When this happens, resolvers may serve outdated information or drop queries entirely, bringing your web and email traffic to a halt. You can quickly diagnose these propagation stalls by running a SOA Lookup to inspect your primary name server configurations, serial numbers, and timer intervals in real-time.

Understanding the Start of Authority (SOA) Record

The Start of Authority record is the foundational piece of every DNS zone. It declares the authoritative name server for the domain, the administrator's email address, and vital timing parameters that dictate how secondary name servers synchronize their zone data with the primary name server.

The Anatomy of SOA Timers

Within the SOA record string, you will find a sequence of five integer values representing time in seconds. Understanding what each timer controls is essential to troubleshooting synchronization faults:

  • Refresh: The time interval that a secondary name server waits before checking the primary server's serial number to see if the zone has changed.
  • Retry: The time interval a secondary server waits before retrying a failed zone transfer attempt.
  • Expire: The maximum time a secondary server will hold zone data without a successful refresh from the primary server. If this timer lapses, the secondary server stops answering queries for the zone.
  • Minimum TTL: The default Time to Live for resource records in the zone that do not explicitly define their own TTL, and the negative caching duration for NXDOMAIN responses.

Why Timers Expire

An expired SOA timer typically occurs due to a prolonged network partition between your primary name server and one or more secondary providers, persistent firewall blocks on TCP/UDP port 53, or an unannounced IP address change on the primary server. When the secondary server cannot reach the primary server to check the serial number before the Expire threshold is reached, it marks its local zone copy as expired and stops serving authoritative answers.

Diagnosing SOA and Zone Transfer Failures

Before you can apply a fix, you need to gather data from your DNS infrastructure. Use native command-line utilities to query your name servers directly and verify their responses.

Querying SOA Records with Dig

Run the dig command from your local machine to check the SOA record for example.com against a specific name server:

dig soa example.com @ns1.example.com

Sample output:

; <<>> DiG 9.18.12-0ubuntu2-Ubuntu <<>> soa example.com @ns1.example.com
;; global options: +print
;; got answers:
;; ->rama
;; aines: 1
example.com.        3600    IN      SOA     ns1.example.com. admin.example.com. 2023102401 7200 3600 1209600 3600
;; AUTHORITY SECTION:
;; symbol: 3600 seconds

In this output, the numbers following the email address represent: Serial (2023102401), Refresh (7200), Retry (3600), Expire (1209600), and Minimum TTL (3600).

Checking Zone Transfer Status

If you suspect secondary servers are failing to sync, test if zone transfers (AXFR) are permitted and operational between your nodes:

dig axfr example.com @ns2.example.com

If the secondary server responds with a refusal or a timeout, verify that your primary name server's firewall allows incoming requests from the secondary server's IP address (such as 192.0.2.50 or IPv6 address 2001:db8::50) on port 53 for both TCP and UDP.

Step-by-Step Guide to Fix Expired SOA Timer

Resolving an expired SOA timer involves restoring communication channels, incrementing zone serial numbers, and tuning timer thresholds to prevent future outages.

Step 1: Restore Network and Firewall Connectivity

Ensure that all secondary name servers can reach the primary name server. Check your cloud provider security groups, local firewalls, and router ACLs. Zone transfers rely heavily on TCP port 53, which is frequently blocked by strict perimeter firewalls.

Step 2: Increment the Zone Serial Number

Open your primary DNS zone file and increment the serial number. Most administrators use the YYYYMMDDNN format. If your current serial is 2023102401, update it to 2023102402:

example.com. IN SOA ns1.example.com. admin.example.com. (
    2023102402 ; Serial
    7200       ; Refresh (2 hours)
    3600       ; Retry (1 hour)
    1209600    ; Expire (14 days)
    3600 )     ; Minimum TTL

Step 3: Reload the Zone on Primary and Secondary Servers

Instruct your primary name server daemon to reload the zone file. For BIND, run:

srndc reload example.com

Next, force a manual zone transfer or reload on your secondary name servers. If you manage the secondary servers via a control panel, navigate to your DNS management settings and select the option to "Force Refresh" or "Sync Zone."

Step 4: Adjust Timer Values for Stability

If your expire timer is set too low (for example, less than 24 hours), transient network glitches can cause premature expiration. Increase your Expire timer to at least 1 week (604800 seconds) or 2 weeks (1209600 seconds) to provide an adequate safety buffer during outages.

Comparing DNS Timer Best Practices

Parameter Recommended Minimum Recommended Standard Common Mistake
Refresh 3600 sec (1 hour) 7200 sec (2 hours) Setting below 900 seconds, causing unnecessary load
Retry 600 sec (10 mins) 3600 sec (1 hour) Setting equal to or higher than the refresh interval
Expire 604800 sec (7 days) 1209600 sec (14 days) Setting below 86400 seconds, risking sudden drop-off
Min TTL 300 sec (5 mins) 3600 sec (1 hour) Setting too high, preventing fast incident response

Common Mistakes and How to Fix Them

  • Forgetting to Increment the Serial Number: If you fix a connectivity issue but fail to increment the zone serial number, secondary servers will assume their local copy is already up to date and will not trigger a zone transfer. Always increment the serial number before reloading.
  • Blocking TCP Port 53: Administrators often open UDP port 53 for standard queries but forget that zone transfers (AXFR and IXFR) require TCP port 53. Ensure both protocols are explicitly allowed.
  • Mismatched Primary IP Addresses: If your primary server's IP address changed and you forgot to update the NS or glue records at your domain registrar, secondary servers will query a dead IP address and eventually expire.

Quick Troubleshooting Checklist

  • Verify primary and secondary name server IP configurations.
  • Check that TCP and UDP port 53 are open across all firewalls.
  • Inspect current timer values using diagnostic tools.
  • Increment the zone serial number in the primary zone file.
  • Force a manual zone reload and check logs for successful transfers.
  • Validate that all secondary servers are actively responding to recursive queries.

Frequently asked questions

What happens when a secondary name server's SOA expire timer is reached?

When the expire timer is reached without a successful zone refresh from the primary server, the secondary server treats its local zone data as invalid. It will then stop responding authoritatively to DNS queries for that domain, resulting in resolution failures for users relying on that name server.

How do I know if my secondary DNS servers are successfully syncing?

You can check the serial numbers returned by all of your authoritative name servers using command-line tools like dig. If every name server reports the exact same serial number, your zone transfers are working correctly. If one or more servers show an older serial number or fail to respond, a synchronization or timer issue exists.

What is the ideal setting for the SOA expire timer?

The industry standard for the SOA expire timer is between one week (604,800 seconds) and two weeks (1,209,600 seconds). This window provides ample time to resolve major network outages or hardware failures on your primary name server without causing the secondary servers to drop the zone.

Why do zone transfers require TCP port 53 instead of UDP?

Standard DNS queries fit easily within UDP packets, but complete zone transfers (AXFR) often exceed the 512-byte UDP limit or the maximum size permitted by EDNS0. TCP guarantees reliable, ordered delivery of large data payloads, which is why name servers switch to TCP port 53 for zone synchronization.

Do I need to restart my entire DNS server software to update SOA timers?

No, you do not need to restart the entire DNS service. You only need to increment the serial number in the zone file, save your changes, and issue a soft reload command specific to your DNS software, such as rndc reload for BIND.

Related articles

Free tools