Hierarchisches Baumdiagramm der DNS-Delegation: Ganz oben der Root-Nameserver, darunter TLD-Server für „.de" und „.com", darunter je ein autoritativer Nameserver für „beispiel.de" bzw. „example.com". Pfeile zeigen die Delegationskette von oben nach unten, beschriftet mit „NS-Eintrag".

DNS Delegation

DNS delegation is the process by which responsibility for a part of the internet's naming system is handed off to another server. This allows the global system of domain names to be managed in a decentralized, division-of-labor fashion.

The internet connects billions of devices, and each one is reachable via an address. So that people can type simple names like “wikipedia.org” instead of such numerical addresses, there is the Domain Name System — DNS for short. It translates names into addresses, much like a phone book translates names into numbers. This system is enormous: no single server can know all the names in the world. DNS delegation is the mechanism that solves this problem. In it, a higher-level entity passes responsibility for a subsection of the namespace on to another entity — thereby declaring itself no longer responsible for that section.

Why DNS would collapse without delegation

Imagine a single authority having to register, verify, and keep up to date every domain name in the world. That would be neither scalable nor secure. If that one entity were to fail, the entire internet would go blind. DNS delegation solves this problem through division of labor: each level of the system is responsible only for its own slice.

This also makes the system resilient. If responsibility for “.de” domains lies with DENIC in Frankfurt and responsibility for “.com” domains lies with Verisign in the US, no single failure can bring everything down. At the same time, every organization can fully manage its own subdomain — such as “department.company.de” — entirely on its own, without having to ask a central authority for permission.

How the chain of referrals is structured

DNS is structured hierarchically like an inverted tree. At the very top sit the root nameservers — there are 13 logical addresses of them worldwide. They don’t know every domain, but they do know which server is responsible for “.de”, “.com”, or “.org”. This responsibility was established through delegation.

When you type “example.de” into a browser, a chain of requests runs in the background. A so-called resolver first asks a root server: who is responsible for “.de”? The root server delegates the request to the server responsible for “.de”. That server in turn knows the nameserver for “example.de” and delegates again. Finally, the nameserver specifically configured for that domain responds with the requested IP address. This chain only works because, whenever a new name is set up, each level deposits what’s called an NS record — a data entry stating: “From now on, this server is responsible for this section.”

It’s important to note: delegation means complete handover. The delegating server provides no further answers for the delegated section. It merely points to the new authority. That authority can then carry out further delegations internally — for example, handing off “shop.example.de” to another server — without needing to inform the level above it.

Where DNS delegation shows up in everyday life and in the news

Anyone who registers their own domain practically always sets up DNS delegation themselves — often without calling it that. When purchasing a domain, you enter the nameservers of your own hosting provider. In doing so, you delegate responsibility for your domain from the registrar (the company you buy the domain from) to the hosting provider’s server. From that moment on, the hosting provider determines which IP address belongs to the domain.

In tech news, the topic comes up when domains are abused. Attackers sometimes seize control of a nameserver and secretly alter the delegation — a method known as DNS hijacking. Suddenly you end up on a fake site even though you typed in the correct address. Companies migrating their IT to the cloud also need to carefully reconfigure delegations — a mistake here can render a website unreachable for hours.

For AI services, DNS delegation is indirectly relevant: major providers like OpenAI or Google run their APIs under their own subdomains and delegate these internally to specialized server groups. Millions of requests per second thus reliably land in the right place — invisible to the user, but technically indispensable.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.