DNS Flag Day on 1 February: Vendors and Operators Push for Standards Compliance
On 1 February, major DNS vendors and operators marked DNS Flag Day to highlight name servers that ignore long-established standards, causing slow and inefficient lookups and blocking new capabilities.
On 1 February, a group of DNS vendors and operators came together to mark DNS Flag Day, an initiative focused on fixing a stubborn technical problem that quietly affects the speed and evolution of the internet. The Domain Name System, or DNS, is often described as the phonebook of the internet: it translates the human-readable website names you type into your browser, such as example.com, into the numerical IP addresses that computers use to route traffic across the network. Without DNS, you would have to memorise long strings of numbers instead of simple names. This critical service relies on many different pieces of software working together according to shared rules, and when some of those pieces ignore the rules, everyone suffers.
The central problem targeted by DNS Flag Day is that some DNS name server implementations, the software that actually answers DNS queries, do not comply with long-established DNS standards. In the DNS world, a name server is a computer or service that holds the records for a domain name and tells other computers where to find it. Standards are agreed technical specifications, often developed openly by the internet engineering community, that ensure different systems made by different vendors can interoperate. A name server that is non-compliant may fail to recognise legitimate query options, return malformed responses, or refuse to support newer record types. DNS Flag Day is a joint effort by several DNS vendors and operators to highlight and address these problems.
This non-compliance causes the DNS to be unnecessarily slow and inefficient. When a resolver, the service that your device or network uses to look up domain names, sends a query to a non-compliant name server, it may not get a usable answer. The resolver then has to retry the query, wait for a timeout, or fall back to older and slower lookup methods. These extra steps happen invisibly every time you load a webpage, send an email, or use an app that connects to the internet. Although each delay is measured in milliseconds, they happen billions of times per day across the global network, wasting time and computing resources for users, website operators, and internet service providers alike. For a website owner, a slow DNS lookup can make even a well-optimised site feel sluggish.
Beyond the current slowdowns, non-compliant name servers also hold back innovation. Network operators and software developers often hesitate to deploy new DNS features and improvements because a significant portion of the infrastructure would not understand them. If a new, more efficient query format or a security-related extension is rolled out, users whose requests pass through older, non-compliant servers would experience failures. To avoid breaking the internet for those users, operators delay or disable these improvements. Over time, this stalls progress across the whole domain name system, and it can delay the adoption of more efficient or more secure ways of handling lookups. The result is that the entire domain name system remains stuck at the pace of its slowest, least compliant participants.
DNS Flag Day aims to change that by providing a clear, cooperative push toward full standards compliance. The initiative brings together multiple vendors and operators, not to single out any particular organisation, but to set a common expectation and a common test. By agreeing that non-compliant behaviour should no longer be tolerated, these groups hope to remove the excuses that have kept outdated software in use. For website owners and IT teams, this is a reminder that the DNS layer of their infrastructure deserves the same attention as web servers and databases. Choosing a DNS provider that keeps its name servers up to date with current standards can directly improve the speed and reliability of your online services. It also reduces the chance that your own domain will be affected by compatibility issues as the industry moves forward.
For everyday internet users and businesses, there are practical steps to protect yourself from the slowdowns caused by non-compliant name servers on the wider internet. You can check which DNS resolver your devices and router are using and switch to a reputable provider known for standards compliance. You can also enable encrypted DNS in your browser or operating system, which adds a layer of privacy and ensures that your queries go to a resolver you trust. Finally, if you operate a website, ask your hosting provider or DNS provider whether their name servers have been tested for DNS Flag Day compliance. Taking these steps helps you avoid some of the inefficiency that the initiative is trying to eliminate. For those who want a resolver that prioritises privacy and standards compliance, a privacy-first encrypted DNS service such as AEU DNS offers another layer of protection and reliability.
Terms explained
- DNS
- The Domain Name System, the internet's phonebook that translates website names into numerical IP addresses.
- name server
- A computer or service that holds the records for a domain name and answers questions about where to find it.
- DNS standards
- Agreed technical rules that make sure different systems and software can work together on the internet.
- resolver
- The service that your device or network uses to look up domain names and get their IP addresses.
- encrypted DNS
- A way of carrying out DNS lookups over a secure, scrambled connection so that no one else can read or alter them.
- DNS Flag Day
- A coordinated initiative by DNS vendors and operators to push for compliance with long-established DNS standards.
How to protect yourself
- Find out which DNS (internet address book) service your computer or router uses, and switch to a well-known provider that keeps its software up to date.
- Turn on encrypted DNS in your web browser or device settings so your internet address lookups are private and cannot be changed in transit.
- If you run a website, ask your hosting or DNS provider whether their name servers have been tested for DNS Flag Day compliance.
- Use a free online DNS testing tool to see if your current resolver correctly handles modern DNS queries.
Source: internetsociety.org
