All MIBs › DNS-SERVER-MIB
Organization: IETF DNS Working Group
Last Updated: 1994-01-28
Category: Web and Application Servers
Description:
Defines managed objects for DNS name server software, allowing SNMP-based access to DNS server configuration, zones, and operational counters.
Imported Objects
From RFC-1213
| mib-2 |
From SNMPv2-CONF
| MODULE-COMPLIANCE | |
| OBJECT-GROUP |
From SNMPv2-SMI
| Counter32 | |
| Gauge32 | |
| IpAddress | |
| MODULE-IDENTITY | |
| OBJECT-IDENTITY | |
| OBJECT-TYPE |
From SNMPv2-TC
| DisplayString | |
| RowStatus | |
| TEXTUAL-CONVENTION | |
| TruthValue |
What Is DNS-SERVER-MIB?
DNS-SERVER-MIB is an IETF/IANA-registered standards-based module for monitoring DNS name server software over SNMP, independent of any particular vendor's DNS implementation. It exposes configuration data (recursion support, implementation identity) alongside operational counters covering query handling, such as authoritative and non-authoritative answers, referrals, and errors. In monitoring terms it is primarily a software-status MIB: dnsServConfigUpTime and dnsServConfigResetTime track how long the DNS service has been running and when it was last reset, while the counter objects reveal whether the server is answering queries successfully or generating an abnormal rate of errors or no-data responses, making this module a foundational building block for dns server monitoring across mixed-vendor deployments. It is a self-contained application-management MIB but is often deployed alongside the general NETWORK-SERVICES-MIB (applTable) for broader application-instance tracking. It is deployed on any server running SNMP-instrumented DNS server software (e.g., BIND or similar) in enterprise and service-provider environments.
IPNetwork Monitor allows you to monitor SNMP objects defined in DNS-SERVER-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
What Can Be Monitored
- DNS server uptime
- query counters (authoritative/non-authoritative/errors)
- recursion configuration
- referral counts
- counter reset time
Supported Devices
- vendor-neutral, standards-based MIB, not tied to a specific manufacturer — applies to any DNS server host (e.g., BIND-based servers)
Monitoring Examples
An operator would poll dnsServConfigUpTime to confirm the DNS process hasn't unexpectedly restarted, and watch dnsServCounterErrors and dnsServCounterAuthNoNames over time to detect a rising rate of failed lookups. A sudden spike in dnsServCounterNonAuthNoDatas or dnsServCounterReferrals relative to dnsServCounterAuthAns could indicate zone data problems or misconfigured delegation. dnsServConfigReset could be invoked to reset counters after such an investigation, and dnsServConfigRecurs confirms whether the server is configured to perform recursive resolution.
OIDs
| OID symbolic | OID numeric | Type | Access | Description |
|---|---|---|---|---|
| dns | 1.3.6.1.2.1.32 | The OID assigned to DNS MIB work by the IANA. | ||
| dnsServMIB | 1.3.6.1.2.1.32.1 | The MIB module for entities implementing the server side of the Domain Name System (DNS) protocol. | ||
| dnsServMIBObjects | 1.3.6.1.2.1.32.1.1 | |||
| dnsServConfig | 1.3.6.1.2.1.32.1.1.1 | |||
| STR dnsServConfigImplementIdent | 1.3.6.1.2.1.32.1.1.1.1 | DisplayString | read-only | The implementation identification string for the DNS server software in use on the system, for example; `FNS-2.1' |
| INT dnsServConfigRecurs | 1.3.6.1.2.1.32.1.1.1.2 | INTEGER | read-write | This represents the recursion services offered by this name server. The values that can be read or written are: available(1) - performs recursion on requests from clients. restricted(2) - recursion is performed on requests only from certain clients, for example; clients on an access control list. unavailable(3) - recursion is not available. |
| DNS dnsServConfigUpTime | 1.3.6.1.2.1.32.1.1.1.3 | DnsTime | read-only | If the server has a persistent state (e.g., a process), this value will be the time elapsed since it started. For software without persistant state, this value will be zero. |
| DNS dnsServConfigResetTime | 1.3.6.1.2.1.32.1.1.1.4 | DnsTime | read-only | If the server has a persistent state (e.g., a process) and supports a `reset' operation (e.g., can be told to re-read configuration files), this value will be the time elapsed since the last time the name server was `reset.' For software that does not have persistence or does not support a `reset' operation, this value will be zero. |
| INT dnsServConfigReset | 1.3.6.1.2.1.32.1.1.1.5 | INTEGER | read-write | Status/action object to reinitialize any persistant name server state. When set to reset(2), any persistant name server state (such as a process) is reinitialized as if the name server had just been started. This value will never be returned by a read operation. When read, one of the following values will be returned: other(1) - server in some unknown state; initializing(3) - server (re)initializing; running(4) - server currently running. |
| dnsServCounter | 1.3.6.1.2.1.32.1.1.2 | |||
| C32 dnsServCounterAuthAns | 1.3.6.1.2.1.32.1.1.2.2 | Counter32 | read-only | Number of queries which were authoritatively answered. |
| C32 dnsServCounterAuthNoNames | 1.3.6.1.2.1.32.1.1.2.3 | Counter32 | read-only | Number of queries for which `authoritative no such name' responses were made. |
| C32 dnsServCounterAuthNoDataResps | 1.3.6.1.2.1.32.1.1.2.4 | Counter32 | read-only | Number of queries for which `authoritative no such data' (empty answer) responses were made. |
| C32 dnsServCounterNonAuthDatas | 1.3.6.1.2.1.32.1.1.2.5 | Counter32 | read-only | Number of queries which were non-authoritatively answered (cached data). |
| C32 dnsServCounterNonAuthNoDatas | 1.3.6.1.2.1.32.1.1.2.6 | Counter32 | read-only | Number of queries which were non-authoritatively answered with no data (empty answer). |
| C32 dnsServCounterReferrals | 1.3.6.1.2.1.32.1.1.2.7 | Counter32 | read-only | Number of requests that were referred to other servers. |
| C32 dnsServCounterErrors | 1.3.6.1.2.1.32.1.1.2.8 | Counter32 | read-only | Number of requests the server has processed that were answered with errors (RCODE values other than 0 and 3). |
| C32 dnsServCounterRelNames | 1.3.6.1.2.1.32.1.1.2.9 | Counter32 | read-only | Number of requests received by the server for names that are only 1 label long (text form - no internal dots). |
| C32 dnsServCounterReqRefusals | 1.3.6.1.2.1.32.1.1.2.10 | Counter32 | read-only | Number of DNS requests refused by the server. |
| C32 dnsServCounterReqUnparses | 1.3.6.1.2.1.32.1.1.2.11 | Counter32 | read-only | Number of requests received which were unparseable. |
| C32 dnsServCounterOtherErrors | 1.3.6.1.2.1.32.1.1.2.12 | Counter32 | read-only | Number of requests which were aborted for other (local) server errors. |
| dnsServCounterTable | 1.3.6.1.2.1.32.1.1.2.13 | not-accessible | Counter information broken down by DNS class and type. | |
| dnsServCounterEntry | 1.3.6.1.2.1.32.1.1.2.13.1 | not-accessible | This table contains count information for each DNS class and type value known to the server. The index allows management software to to create indices to the table to get the specific information desired, e.g., number of queries over UDP for records with type value `A' which came to this server. In order to prevent an uncontrolled expansion of rows in the table; if dnsServCounterRequests is 0 and dnsServCounterResponses is 0, then the row does not exist and `no such' is returned when the agent is queried for such instances. | |
| DNS dnsServCounterOpCode | 1.3.6.1.2.1.32.1.1.2.13.1.1 | DnsOpCode | not-accessible | The DNS OPCODE being counted in this row of the table. |
| DNS dnsServCounterQClass | 1.3.6.1.2.1.32.1.1.2.13.1.2 | DnsClass | not-accessible | The class of record being counted in this row of the table. |
| DNS dnsServCounterQType | 1.3.6.1.2.1.32.1.1.2.13.1.3 | DnsType | not-accessible | The type of record which is being counted in this row in the table. |
| INT dnsServCounterTransport | 1.3.6.1.2.1.32.1.1.2.13.1.4 | INTEGER | not-accessible | A value of udp(1) indicates that the queries reported on this row were sent using UDP. A value of tcp(2) indicates that the queries reported on this row were sent using TCP. A value of other(3) indicates that the queries reported on this row were sent using a transport that was neither TCP nor UDP. |
| C32 dnsServCounterRequests | 1.3.6.1.2.1.32.1.1.2.13.1.5 | Counter32 | read-only | Number of requests (queries) that have been recorded in this row of the table. |
| C32 dnsServCounterResponses | 1.3.6.1.2.1.32.1.1.2.13.1.6 | Counter32 | read-only | Number of responses made by the server since initialization for the kind of query identified on this row of the table. |
| dnsServOptCounter | 1.3.6.1.2.1.32.1.1.3 | |||
| C32 dnsServOptCounterSelfAuthAns | 1.3.6.1.2.1.32.1.1.3.1 | Counter32 | read-only | Number of requests the server has processed which originated from a resolver on the same host for which there has been an authoritative answer. |
| C32 dnsServOptCounterSelfAuthNoNames | 1.3.6.1.2.1.32.1.1.3.2 | Counter32 | read-only | Number of requests the server has processed which originated from a resolver on the same host for which there has been an authoritative no such name answer given. |
| C32 dnsServOptCounterSelfAuthNoDataResps | 1.3.6.1.2.1.32.1.1.3.3 | Counter32 | read-only | Number of requests the server has processed which originated from a resolver on the same host for which there has been an authoritative no such data answer (empty answer) made. |
| C32 dnsServOptCounterSelfNonAuthDatas | 1.3.6.1.2.1.32.1.1.3.4 | Counter32 | read-only | Number of requests the server has processed which originated from a resolver on the same host for which a non-authoritative answer (cached data) was made. |
| C32 dnsServOptCounterSelfNonAuthNoDatas | 1.3.6.1.2.1.32.1.1.3.5 | Counter32 | read-only | Number of requests the server has processed which originated from a resolver on the same host for which a `non-authoritative, no such data' response was made (empty answer). |
| C32 dnsServOptCounterSelfReferrals | 1.3.6.1.2.1.32.1.1.3.6 | Counter32 | read-only | Number of queries the server has processed which originated from a resolver on the same host and were referred to other servers. |
| C32 dnsServOptCounterSelfErrors | 1.3.6.1.2.1.32.1.1.3.7 | Counter32 | read-only | Number of requests the server has processed which originated from a resolver on the same host which have been answered with errors (RCODEs other than 0 and 3). |
| C32 dnsServOptCounterSelfRelNames | 1.3.6.1.2.1.32.1.1.3.8 | Counter32 | read-only | Number of requests received for names that are only 1 label long (text form - no internal dots) the server has processed which originated from a resolver on the same host. |
| C32 dnsServOptCounterSelfReqRefusals | 1.3.6.1.2.1.32.1.1.3.9 | Counter32 | read-only | Number of DNS requests refused by the server which originated from a resolver on the same host. |
| C32 dnsServOptCounterSelfReqUnparses | 1.3.6.1.2.1.32.1.1.3.10 | Counter32 | read-only | Number of requests received which were unparseable and which originated from a resolver on the same host. |
| C32 dnsServOptCounterSelfOtherErrors | 1.3.6.1.2.1.32.1.1.3.11 | Counter32 | read-only | Number of requests which were aborted for other (local) server errors and which originated on the same host. |
| C32 dnsServOptCounterFriendsAuthAns | 1.3.6.1.2.1.32.1.1.3.12 | Counter32 | read-only | Number of queries originating from friends which were authoritatively answered. The definition of friends is a locally defined matter. |
| C32 dnsServOptCounterFriendsAuthNoNames | 1.3.6.1.2.1.32.1.1.3.13 | Counter32 | read-only | Number of queries originating from friends, for which authoritative `no such name' responses were made. The definition of friends is a locally defined matter. |
| C32 dnsServOptCounterFriendsAuthNoDataResps | 1.3.6.1.2.1.32.1.1.3.14 | Counter32 | read-only | Number of queries originating from friends for which authoritative no such data (empty answer) responses were made. The definition of friends is a locally defined matter. |
| C32 dnsServOptCounterFriendsNonAuthDatas | 1.3.6.1.2.1.32.1.1.3.15 | Counter32 | read-only | Number of queries originating from friends which were non-authoritatively answered (cached data). The definition of friends is a locally defined matter. |
| C32 dnsServOptCounterFriendsNonAuthNoDatas | 1.3.6.1.2.1.32.1.1.3.16 | Counter32 | read-only | Number of queries originating from friends which were non-authoritatively answered with no such data (empty answer). |
| C32 dnsServOptCounterFriendsReferrals | 1.3.6.1.2.1.32.1.1.3.17 | Counter32 | read-only | Number of requests which originated from friends that were referred to other servers. The definition of friends is a locally defined matter. |
| C32 dnsServOptCounterFriendsErrors | 1.3.6.1.2.1.32.1.1.3.18 | Counter32 | read-only | Number of requests the server has processed which originated from friends and were answered with errors (RCODE values other than 0 and 3). The definition of friends is a locally defined matter. |
| C32 dnsServOptCounterFriendsRelNames | 1.3.6.1.2.1.32.1.1.3.19 | Counter32 | read-only | Number of requests received for names from friends that are only 1 label long (text form - no internal dots) the server has processed. |
| C32 dnsServOptCounterFriendsReqRefusals | 1.3.6.1.2.1.32.1.1.3.20 | Counter32 | read-only | Number of DNS requests refused by the server which were received from `friends'. |
| C32 dnsServOptCounterFriendsReqUnparses | 1.3.6.1.2.1.32.1.1.3.21 | Counter32 | read-only | Number of requests received which were unparseable and which originated from `friends'. |
| C32 dnsServOptCounterFriendsOtherErrors | 1.3.6.1.2.1.32.1.1.3.22 | Counter32 | read-only | Number of requests which were aborted for other (local) server errors and which originated from `friends'. |
| dnsServZone | 1.3.6.1.2.1.32.1.1.4 | |||
| dnsServZoneTable | 1.3.6.1.2.1.32.1.1.4.1 | not-accessible | Table of zones for which this name server provides information. Each of the zones may be loaded from stable storage via an implementation-specific mechanism or may be obtained from another name server via a zone transfer. If name server doesn't load any zones, this table is empty. | |
| dnsServZoneEntry | 1.3.6.1.2.1.32.1.1.4.1.1 | not-accessible | An entry in the name server zone table. New rows may be added either via SNMP or by the name server itself. | |
| DNS dnsServZoneName | 1.3.6.1.2.1.32.1.1.4.1.1.1 | DnsNameAsIndex | not-accessible | DNS name of the zone described by this row of the table. This is the owner name of the SOA RR that defines the top of the zone. This is name is in uppercase: characters 'a' through 'z' are mapped to 'A' through 'Z' in order to make the lexical ordering useful. |
| DNS dnsServZoneClass | 1.3.6.1.2.1.32.1.1.4.1.1.2 | DnsClass | not-accessible | DNS class of the RRs in this zone. |
| DNS dnsServZoneLastReloadSuccess | 1.3.6.1.2.1.32.1.1.4.1.1.3 | DnsTime | read-only | Elapsed time in seconds since last successful reload of this zone. |
| DNS dnsServZoneLastReloadAttempt | 1.3.6.1.2.1.32.1.1.4.1.1.4 | DnsTime | read-only | Elapsed time in seconds since last attempted reload of this zone. |
| IP dnsServZoneLastSourceAttempt | 1.3.6.1.2.1.32.1.1.4.1.1.5 | IpAddress | read-only | IP address of host from which most recent zone transfer of this zone was attempted. This value should match the value of dnsServZoneSourceSuccess if the attempt was succcessful. If zone transfer has not been attempted within the memory of this name server, this value should be 0.0.0.0. |
| ROW dnsServZoneStatus | 1.3.6.1.2.1.32.1.1.4.1.1.6 | RowStatus | read-create | The status of the information represented in this row of the table. |
| C32 dnsServZoneSerial | 1.3.6.1.2.1.32.1.1.4.1.1.7 | Counter32 | read-only | Zone serial number (from the SOA RR) of the zone represented by this row of the table. If the zone has not been successfully loaded within the memory of this name server, the value of this variable is zero. |
| T/F dnsServZoneCurrent | 1.3.6.1.2.1.32.1.1.4.1.1.8 | TruthValue | read-only | Whether the server's copy of the zone represented by this row of the table is currently valid. If the zone has never been successfully loaded or has expired since it was last succesfully loaded, this variable will have the value false(2), otherwise this variable will have the value true(1). |
| IP dnsServZoneLastSourceSuccess | 1.3.6.1.2.1.32.1.1.4.1.1.9 | IpAddress | read-only | IP address of host which was the source of the most recent successful zone transfer for this zone. If unknown (e.g., zone has never been successfully transfered) or irrelevant (e.g., zone was loaded from stable storage), this value should be 0.0.0.0. |
| dnsServZoneSrcTable | 1.3.6.1.2.1.32.1.1.4.2 | not-accessible | This table is a list of IP addresses from which the server will attempt to load zone information using DNS zone transfer operations. A reload may occur due to SNMP operations that create a row in dnsServZoneTable or a SET to object dnsServZoneReload. This table is only used when the zone is loaded via zone transfer. | |
| dnsServZoneSrcEntry | 1.3.6.1.2.1.32.1.1.4.2.1 | not-accessible | An entry in the name server zone source table. | |
| DNS dnsServZoneSrcName | 1.3.6.1.2.1.32.1.1.4.2.1.1 | DnsNameAsIndex | not-accessible | DNS name of the zone to which this entry applies. |
| DNS dnsServZoneSrcClass | 1.3.6.1.2.1.32.1.1.4.2.1.2 | DnsClass | not-accessible | DNS class of zone to which this entry applies. |
| IP dnsServZoneSrcAddr | 1.3.6.1.2.1.32.1.1.4.2.1.3 | IpAddress | not-accessible | IP address of name server host from which this zone might be obtainable. |
| ROW dnsServZoneSrcStatus | 1.3.6.1.2.1.32.1.1.4.2.1.4 | RowStatus | read-create | The status of the information represented in this row of the table. |
| dnsServMIBGroups | 1.3.6.1.2.1.32.1.2 | |||
| dnsServConfigGroup | 1.3.6.1.2.1.32.1.2.1 | A collection of objects providing basic configuration control of a DNS name server. | ||
| dnsServCounterGroup | 1.3.6.1.2.1.32.1.2.2 | A collection of objects providing basic instrumentation of a DNS name server. | ||
| dnsServOptCounterGroup | 1.3.6.1.2.1.32.1.2.3 | A collection of objects providing extended instrumentation of a DNS name server. | ||
| dnsServZoneGroup | 1.3.6.1.2.1.32.1.2.4 | A collection of objects providing configuration control of a DNS name server which loads authoritative zones. | ||
| dnsServMIBCompliances | 1.3.6.1.2.1.32.1.3 | |||
| dnsServMIBCompliance | 1.3.6.1.2.1.32.1.3.1 | The compliance statement for agents implementing the DNS name server MIB extensions. |
FAQ
How would DNS-SERVER-MIB help me confirm a BIND server has been stable and answering queries correctly?
dnsServConfigUpTime and dnsServConfigResetTime show how long the DNS service has been running and when it was last reset, while the counter objects for authoritative/non-authoritative answers, referrals, and errors reveal whether the server is answering successfully or generating an abnormal rate of errors.
Can DNS-SERVER-MIB tell me if a name server is misconfigured for recursion?
Yes, it exposes recursion-support configuration alongside implementation identity, so polling those objects confirms whether recursion is enabled as expected on a given DNS server instance.
RFC description
DNS server management MIB for Domain Name System server monitoring.
Start monitoring DNS server host software, e.g. BIND (vendor-neutral, IETF/IANA standard) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.