Re: Our Own DNS vs. GoDaddy's

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



<skennedy@xxxxxxxxxxxxxxxx> wrote in message
news:1160056937.947533.4700@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
We have multiple domains registered with GoDaddy. GoDaddy offers a free
service called 'True Total DNS Control' which enables us to manages DNS
records on their admin site, if our domain DNS is 'parked' with them.
We've used this service before, and DNSSTUFF.com reports that the DNS
response is A+.

Now then, what's the advantage of setting up our own public DNS server
over using GoDaddy's service?

For all but the largest companies (in terms of Internet presence,
e.g., Amazon, LandsEnd, some Universities) the REGISTRAR
is to be STRONGLY preferred.

Leave it at GoDaddy.

24/7 support with immediate backup/restore on redundant
hardware and their DNS is "close to the Internet backbone".
Multiple servers and multiply routed.

You would need to put up two servers to comply with Internet
"business rules" (although many people don't do this), and you
really don't want to mix your PUBLIC resolution in with your
other (outbound) DNS for security and management issues.

Any additional services (outward facing) on your own Servers
are just another point of attack (i.e., "increase the attack surface")
which might be affected by a misconfiguration or (more likely)
by an as yet undiscovered bug.

Since a quality Registrar gives you a "web page" to manage all
of this it is almost always preferable.

Any advice/help would be appreciated.


--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]


.



Relevant Pages

  • Re: How Secure is ".Local?"
    ... > dozen servers and ~500 websites/public domains. ... Shadow DNS ... Is your DC on the Internet? ... >>It is not going to provide your zone info to anyone ...
    (microsoft.public.win2000.dns)
  • RE: New Forest - Old Domain - Plus DMZ - Help Please
    ... Make sure Windows XP client should use the AD DNS ... The Cert should match the name in Internet. ... New Forest - Old Domain - Plus DMZ - Help Please ... vast majority of our inside production equipment is 2003 servers and XP ...
    (microsoft.public.windows.server.migration)
  • Re: EBS 2008 and e-mail issues
    ... Whilst doing this they used the DNS ... I have reset all the firewalls rules back to default on the TMG server, ... Removed the DNS servers ... On 2003 SBS one would probably easily solve this by running the internet ...
    (microsoft.public.windows.server.sbs)
  • Re: Active Directory and child DNS Zone
    ... > Our internal and external DNS domains are both the same - mycompany.com. ... > hosts our external domain and it only contains entries for our web servers ... >>> but the test bed isn't a true picture (no internet access to test VPN, ...
    (microsoft.public.windows.server.dns)
  • Re: DNS design questions
    ... We're a medium size college campus with about 10,000 users and the CIO wants to have DNS locally housed. ... only a hand full to a few dozen max "Internet servers" while ... how big of a security issue really is allowing the "external" DNS server pull a zone transfer from an internal one? ...
    (microsoft.public.windows.server.dns)