nslookup Non-Authoritative Answer: What It Means and What To Do (2026)

29 July, 2026 • 168 views • 9 minutes read

"Non-authoritative answer" in nslookup is normal — 99.9% of queries return it. Learn what it means, when it matters, and how to get authoritative answers.

nslookup Non-Authoritative Answer: What It Means and What To Do (2026)

Quick Answer: You ran an nslookup command and saw "Non-authoritative answer". Here's what it means:

It means your DNS server answered from its cache instead of querying the domain's official nameservers. It happens in 99.9% of nslookup queries. You don't need to do anything about it.

The answer itself is correct — the "non-authoritative" label describes where the answer came from, not whether the answer is accurate.

If you want to understand why it happens, when it actually matters, and how to get a truly authoritative answer when you need one — read on.

Table of Contents

  1. What Does "Non-Authoritative Answer" Mean in nslookup?
  2. Authoritative vs Non-Authoritative DNS: The Core Difference
  3. How DNS Actually Works (Why Non-Authoritative is Normal)
  4. Reading a Full nslookup Output
  5. How to Get an Authoritative Answer When You Need One
  6. nslookup MX Record Lookup — With Examples
  7. TXT Record Lookup with nslookup
  8. When Non-Authoritative Actually Is a Problem
  9. Checking DNS Records Without the Command Line
  10. Frequently Asked Questions

1. What Does "Non-Authoritative Answer" Mean in nslookup?

When you run an nslookup command, the output looks something like this:

$ nslookup example.com

Server:  8.8.8.8
Address: 8.8.8.8#53

Non-authoritative answer:
Name:    example.com
Address: 93.184.216.34

The line "Non-authoritative answer" is nslookup telling you:

"I got this answer from a DNS server that is NOT the official (authoritative) server for this domain — it answered from its cache."

Is the information wrong? Almost never. The IP address returned is the same IP address that the authoritative server would return. The "non-authoritative" label is about where the answer came from, not about whether the answer is accurate.

Think of it like getting directions from a local resident who knows the area versus calling the city planning office directly. The directions are the same. The local resident is "non-authoritative" in the technical sense — they're not the official source — but they're giving you correct information.

2. Authoritative vs Non-Authoritative DNS: The Core Difference

Understanding this distinction requires knowing what "authoritative" means in the DNS world.

Authoritative DNS Server

An authoritative DNS server is the server that owns the official DNS records for a domain. When you register a domain and set up DNS hosting (through Cloudflare, your registrar, or a dedicated DNS provider), those DNS servers become the authoritative nameservers for your domain.

When someone queries one of these authoritative servers directly, the response comes back without the "Non-authoritative answer" label:

$ nslookup example.com ns1.example.com
Server:  ns1.example.com
Address: 205.251.196.1#53

Name:    example.com
Address: 93.184.216.34

No "Non-authoritative answer" line — because you queried the authoritative server directly.

Non-Authoritative DNS Server (Recursive/Caching)

A non-authoritative server is any DNS server that doesn't own the records but answers from its cache. These servers:

  • Act as middlemen between you and the authoritative servers
  • Cache answers temporarily (based on TTL) to speed up future queries
  • Include popular resolvers like Google (8.8.8.8), Cloudflare (1.1.1.1), and your ISP's DNS
  • Answer "non-authoritatively" because they're relaying cached copies
DNS Server Type Who Uses It Authoritative For Returns
Authoritative Domain owners / DNS hosts Specific domains they manage Direct, official records
Recursive/Caching ISPs, Google 8.8.8.8, Cloudflare 1.1.1.1 Nothing (they forward) Cached copies
Your local DNS Your router/computer Nothing Cached copies

3. How DNS Actually Works (Why Non-Authoritative is Normal)

Here's the full DNS resolution process — which explains why almost every nslookup query returns "Non-authoritative answer":

Step 1: You Run nslookup

nslookup example.com

Your terminal sends this query to the DNS server configured on your device. This is almost always your ISP's DNS server, Google (8.8.8.8), Cloudflare (1.1.1.1), or your router.

Step 2: Your DNS Server Checks Its Cache

If your DNS server has recently resolved example.com for any of its users, it has a cached copy. It returns that cached copy to you immediately — with the "Non-authoritative answer" label, because the answer came from cache, not directly from example.com's nameservers.

Step 3: If Not Cached — The Full Resolution Chain

If the record isn't cached, your DNS server starts climbing the DNS hierarchy:

Your DNS server
    → asks Root DNS Servers ("who handles .com?")
    → asks .com TLD Servers ("who handles example.com?")
    → asks example.com's Authoritative Nameservers ("what's the A record?")
    → gets the answer
    → caches it
    → returns it to you (still marked "Non-authoritative")

The Three-Tier DNS System

Tier 1: Root Name Servers (13 servers worldwide)
         ↓ "I know who handles .com domains"
Tier 2: TLD Name Servers (.com, .net, .org, etc.)
         ↓ "I know who handles example.com"
Tier 3: Authoritative Name Servers (specific to each domain)
         ↓ "Here's the actual IP address for example.com"

4. Reading a Full nslookup Output

Here's a complete nslookup output with every element explained:

$ nslookup example.com

Server:  8.8.8.8          ← The DNS server you queried
Address: 8.8.8.8#53       ← Its IP address and port 53 (DNS port)

Non-authoritative answer:  ← Response is from cache, not authoritative server
Name:    example.com       ← The domain you queried
Address: 93.184.216.34     ← The A record (IPv4 address)

Multiple Addresses

Some domains return multiple IP addresses (for load balancing):

$ nslookup google.com

Server:  8.8.8.8
Address: 8.8.8.8#53

Non-authoritative answer:
Name:    google.com
Address: 142.250.185.78
Address: 142.250.185.110
Address: 142.250.185.100

CNAME in the Output

$ nslookup www.example.com

Non-authoritative answer:
www.example.com    canonical name = example.com.
Name:    example.com
Address: 93.184.216.34

5. How to Get an Authoritative Answer When You Need One

Most of the time, the non-authoritative answer is perfectly fine. But if you need the official, most current record — for example, when you've just updated DNS records and want to confirm the change — here's how to query the authoritative server directly.

Step 1: Find the Authoritative Nameservers

# Method 1: nslookup
nslookup -type=ns example.com

# Method 2: nslookup with SOA record
nslookup -type=soa example.com

Or use Rankcept's free DNS Lookup tool — enter your domain and instantly see all NS records without typing any commands.

Step 2: Query the Authoritative Server Directly

nslookup example.com ns1.example.com

Output (no "Non-authoritative answer" line):

Server:  ns1.example.com
Address: 205.251.196.1#53

Name:    example.com
Address: 93.184.216.34

No "Non-authoritative answer" — you're getting the official record directly from the source.

Step 3: Force a Fresh Lookup by Clearing Cache

If you're testing a recent DNS change, bypass the cache entirely:

# On Windows
ipconfig /flushdns

# On macOS
sudo dscacheutil -flushcache

# On Linux (systemd-resolved)
sudo resolvectl flush-caches

Then re-run nslookup against a fresh resolver like 8.8.8.8 to confirm propagation.

6. nslookup MX Record Lookup — With Examples

MX (Mail Exchange) records tell mail servers where to deliver email for a domain. Checking MX records with nslookup is one of the most common troubleshooting tasks for email delivery issues.

Basic MX Lookup

nslookup -type=mx example.com

Output:

Server:  8.8.8.8
Address: 8.8.8.8#53

Non-authoritative answer:
example.com    mail exchanger = 10 mail.example.com
example.com    mail exchanger = 20 mail2.example.com

The numbers (10, 20) are priority values — lower number = higher priority.

Field Meaning
mail exchanger = 10 Priority 10 (primary mail server)
mail.example.com Hostname of the mail server
Multiple entries Fallback servers in priority order

7. TXT Record Lookup with nslookup

TXT records have multiple uses: SPF email authentication, DKIM keys, domain verification for Google/Microsoft, and DMARC policies.

Basic TXT Lookup

nslookup -type=txt example.com

Output:

Server:  8.8.8.8
Address: 8.8.8.8#53

Non-authoritative answer:
example.com    text = "v=spf1 include:_spf.google.com ~all"
example.com    text = "google-site-verification=abc123xyz"

8. When Non-Authoritative Actually Is a Problem

In most cases, non-authoritative answers are fine. Here are the rare situations where they can cause genuine issues:

1. You Just Changed DNS Records

If you changed an A record or MX record and ran nslookup immediately, you might get the old cached value. This isn't a problem with your DNS change — it's just the cache hasn't expired yet.

Pro tip: Check the TTL of your record (visible in authoritative answers) — that's how long caches keep the old value.

2. DNS Propagation Debugging

During DNS propagation, different DNS servers around the world may have different cached values — some showing the old record, others showing the new one. To see what the authoritative server says (the definitive answer), query it directly as shown in Section 5.

3. Split-Horizon DNS / Internal Records

Some domains return different records on internal vs external DNS (split-horizon DNS). A public resolver like 8.8.8.8 won't see internal records — query your internal DNS or the authoritative server directly.

9. Checking DNS Records Without the Command Line

Rankcept's free DNS Lookup tool lets you check any DNS record type — A, AAAA, MX, TXT, CNAME, NS, SOA — from any browser with no installation required.

Record Type What It Does
A records IPv4 address for a domain
AAAA records IPv6 address for a domain
MX records Mail server configuration
TXT records SPF, DKIM, DMARC, verification
CNAME records Domain aliasing
NS records Nameservers for the domain
SOA records Zone authority & TTL info

Just enter your domain, pick the record type, and get instant results — perfect for verifying DNS changes, checking propagation, or auditing your email configuration.

10. Frequently Asked Questions

Is "Non-authoritative answer" a problem?

No. It's the default behavior for 99.9% of nslookup queries. The answer is correct — it just came from a caching DNS server rather than the domain's authoritative nameservers.

How do I get an authoritative nslookup answer?

Find the domain's nameservers with nslookup -type=ns domain.com, then query them directly: nslookup domain.com ns1.domain.com. The output will not include the "Non-authoritative answer" line.

What's the difference between authoritative and recursive DNS?

An authoritative DNS server holds the official records for a domain. A recursive (caching) resolver finds and caches those records on behalf of users. Recursive resolvers return "non-authoritative" answers from their cache.

Why does nslookup say "Non-authoritative answer" for my own domain?

Because your computer's DNS server (router, ISP, or public resolver like 8.8.8.8) is answering from cache instead of querying your domain's nameservers. Query your nameservers directly to get the authoritative answer.

Does non-authoritative mean the DNS answer is fake or wrong?

No. "Non-authoritative" describes the source of the answer, not its accuracy. Cached answers are copies of what the authoritative servers returned earlier.

How do I check DNS records online without nslookup?

Use a free web-based DNS lookup tool like Rankcept DNS Lookup — no command line needed.

What is TTL and why does it matter?

TTL (Time to Live) tells caching DNS servers how long to keep a record before re-checking with the authoritative server. Lower TTL = faster propagation after changes; higher TTL = faster lookups but slower updates.

Why do I see multiple IP addresses in nslookup?

Domains often use multiple A records for load balancing and redundancy. Each address points to a different server handling the same domain.

Can I force nslookup to use a specific DNS server?

Yes: nslookup domain.com 8.8.8.8 queries Google's resolver, nslookup domain.com 1.1.1.1 queries Cloudflare's, or specify any other server IP.

What does "Server: UnKnown" mean in nslookup?

It means nslookup couldn't resolve the name of the DNS server it's using (just a reverse-DNS display issue). The lookup still works correctly — check the IP address in the next line.

Final Verdict

"Non-authoritative answer" is normal, expected, and almost never a problem. It simply means your query was answered by a caching DNS server rather than the domain's official nameservers. The data is correct 99.9% of the time.

The only time you need an authoritative answer is when verifying recent DNS changes or debugging propagation issues — and in those cases, just query the domain's nameservers directly or use a free DNS Lookup tool to check all record types in seconds.

0 of 0 ratings