Single-Nameserver Domains: One Record from Oblivion
Published
Figures as of 2026-08-16 · methodology v9. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade or name an individual registrant’s domain.
The headline: 290,673 domains are one server from the dark
Across the 376,928,781 domains graded in our August 2026 census, 290,673 list exactly one nameserver record — about one in every 1,296 domains on the graded web. For each of them, a single point of failure sits between the domain and total blackout. If that one delegation target stops answering, everything under the name stops at once: the website, incoming email, every subdomain, every API. Not degraded. Gone.
The number is smaller than we expected when we pulled this cut, and that is part of the story. DNS’s oldest redundancy rule mostly held. But it held at the floor: 56.1% of the graded web runs on exactly two nameserver records, the minimum the protocol has demanded since 1987, and only 21.8% of domains carry anything beyond it. The internet’s naming layer is not un-redundant. It is minimally redundant, everywhere, by default.
Key numbers
- 290,673 of 376,928,781 graded domains list a single nameserver record — 0.08%, roughly 1 in 1,296 (August 2026 census).
- 56.1% of the graded web — 211,351,017 domains — runs on exactly two NS records, the protocol minimum.
- Only 17.5% of domains (66,099,439) list three or more nameservers.
- The median domain has exactly 2 nameserver records; 10.1% list four, typical of large managed-DNS platforms.
- 2.0% of domains (7,201,091) list five or more nameservers; the maximum observed was 192 NS records, held by 14 domains.
What does a nameserver record actually do?
Every domain delegates its existence to a set of nameservers. When anyone anywhere asks “where is this domain?” — a browser loading the site, a mail server delivering a message, a payment processor validating a webhook — the question ultimately routes to one of the servers named in the domain’s NS records. Those servers hold the answers: the web address, the mail routes, the verification tokens, everything.
The delegation is the domain, in a practical sense. A web server outage takes down the website. A nameserver outage takes down the name, and the name is what every other service hangs off. That is why the original DNS specification required at least two nameservers from the very beginning, and why later operational guidance told operators to place them on separate networks in separate locations. (Those requirements come from RFC 1034, published in 1987, and RFC 2182, the 1997 best-practices document on secondary DNS — industry context, not census data.)
So the single-NS cohort is not a cohort of domains with a weak configuration. It is a cohort of domains violating the oldest resilience rule the DNS has, one that predates the web itself.
How many nameservers does a typical domain have?
Two. Not “around two” — exactly two, for more than half of everything we graded. Here is the full distribution across the 376.9 million graded domains:
| NS records listed | Domains | Share of graded web |
|---|---|---|
| 1 | 290,673 | 0.08% |
| 2 | 211,351,017 | 56.1% |
| 3 | 20,936,970 | 5.6% |
| 4 | 37,961,378 | 10.1% |
| 5 | 2,808,001 | 0.7% |
| 6 | 1,751,972 | 0.5% |
| 7 | 323,515 | 0.09% |
| 8 | 2,252,649 | 0.6% |
| 9 or more | 64,954 | 0.02% |
The shape says a lot about who actually decides this setting. Almost nobody chooses a nameserver count. Their DNS provider does. The towering bar at two is the signature of the mass-market default — registrar DNS and large CDN-style providers typically hand every customer a pair of names. The secondary bump at four matches the assignment pattern of the big managed-DNS platforms. The blip at eight (2.25 million domains) and even the strange little spike at twelve (43,799 domains) look like provider defaults too: counts that specific don’t happen 43,799 times by individual choice.
Which reframes the single-NS cohort. These 290,673 domains are mostly not the work of a sysadmin who weighed the trade-offs and picked one server. They are what’s left when the default didn’t apply — self-hosted DNS on one box, a secondary that was deleted and never replaced, a migration that finished halfway. The distribution is a picture of an internet where resilience is whatever the provider shipped, and the failures are the places where no provider was standing behind the domain at all.
What actually happens when the one nameserver dies?
Walk through it, because the failure is broader than people expect.
The nameserver stops answering — a crashed box, an expired hosting invoice, a routing incident, a DDoS on the provider. Resolvers around the world keep serving cached answers for a while, so the outage arrives in slow motion: visitors with warm caches still connect, everyone else gets nothing. As caches expire over the following minutes and hours, the domain fades from the internet region by region.
Then the second-order failures start. Inbound email doesn’t bounce immediately — sending servers queue and retry — but nothing is delivered, and after a few days of retries the mail returns to sender as undeliverable. Password resets to addresses at the domain stop arriving. Domain-validated certificate renewals fail, because the CA can’t resolve the name to check it. Third-party services that verify the domain by DNS lookup mark it dead. A web outage is an inconvenience on one channel. A nameserver outage is every channel at once, plus the recovery channels you’d use to fix it.
And here is the quiet part: a domain with two nameservers survives this entire scenario without anyone noticing. The second server answers, resolvers fail over automatically, and the incident becomes a log line instead of an outage. The whole mechanism is free. Redundant DNS is bundled into essentially every registrar and DNS service on the market; the single-NS cohort isn’t paying less, it has just drifted outside the default.
Is two nameservers actually enough?
This is where we owe you the honest caveat, and it cuts in both directions.
A listed count understates real redundancy for big providers. Modern DNS platforms run anycast: one nameserver name can front dozens or hundreds of physical servers spread across continents, all answering to the same address. A domain listing two NS records at a major anycast provider has vastly more real-world resilience than the number “2” suggests. Counting names is not counting servers.
And a listed count overstates redundancy for everyone else. Two NS records that resolve to the same subnet, the same rack, or the same single upstream provider are paper redundancy — two names, one failure domain. The 1997 best-practice guidance exists precisely because operators kept deploying “redundant” secondaries next to their primaries. Our NS-count cut cannot see network topology, so it cannot say how many of the 211 million two-NS domains have genuinely independent servers behind the pair.
So read this report as measuring the listed-names layer of DNS redundancy: the layer the protocol requires, the layer a registrar shows you, the layer you can fix in five minutes. The routing-diversity layer — how many independent networks actually stand behind those names — is a different measurement, and a companion piece to this one. What we can say without qualification is that a single NS record is the one configuration with no redundancy at either layer. There is no anycast cloud, no hidden secondary, no interpretation under which one delegation target is two.
The long tail: the domains with 192 nameservers
At the other end of the distribution, 64,954 domains list nine or more nameservers, and the extreme tail gets genuinely odd: single domains listing 49, 50, 87, 108 NS records. The maximum we observed was 192 nameserver records, shared by 14 domains.
Past six or so, extra NS records stop buying resilience and start costing it. DNS responses have size limits; a delegation set that bloated forces truncation and fallback behaviour, and resolvers will only ever try a handful of the listed servers anyway. A 192-server delegation is not a fortress. It is almost certainly a misconfiguration — a script appending records without pruning, or a migration gone feral. The healthy range in the data and in operational practice is two to eight, which conveniently is where the vast majority of the graded web already lives.
How we measured this
- Population and denominator: 376,928,781 graded domain rows from the August 2026 census round (figures as of 2026-08-16, methodology v9). Domains with no NS record data are excluded from the distribution table but included in the denominator. Ungraded, unreachable and dead domains are included in the graded total.
- What we counted: the number of NS records in each domain’s delegation as observed at scan time from our EU-based measurement infrastructure. This is a point-in-time count of listed nameserver names.
- What the count cannot see: anycast. One listed name may front many physical servers (real redundancy exceeds the count); several listed names may share one network or provider (real redundancy falls short of the count). Treat NS count as the listed-names layer of redundancy only, not a full availability picture.
- No uptime claims: we measured configuration, not outages. The failure scenarios described are the standard consequences of a delegation with no surviving nameserver — industry knowledge, not an incident dataset.
- Protocol and best-practice references (RFC 1034’s two-server requirement, RFC 2182’s diversity guidance, response-size behaviour at extreme NS counts) are industry context, labelled as such, not census measurements.
- Aggregate only. We publish distribution counts. We never name, grade or publish data about an individual registrant’s domain.
- Data is stored and processed within the EU.
FAQ
How many nameservers should a domain have? Two is the protocol minimum and the internet’s overwhelming default — 56.1% of the 376.9 million domains we graded in August 2026 list exactly two. Two at a reputable provider with independent infrastructure is fine for most domains; three or four adds margin. Past eight, additional records deliver no practical benefit and can cause response-size problems.
Is one nameserver ever acceptable? No configuration we can think of makes it the right choice, and the DNS specification has required at least two since 1987. One nameserver means one point of failure for the website, inbound email, certificate renewal and every DNS-verified service at once. In our August 2026 census, 290,673 domains — about 1 in 1,296 — were in this state, almost certainly by accident rather than decision.
What happens if all my nameservers go down? Your domain disappears progressively as resolver caches expire: the website becomes unreachable, then inbound mail starts queueing at sender servers, typically bouncing after a few days of failed retries. Certificate renewals and DNS-based verifications fail too. With at least two genuinely independent nameservers, a single server failure is invisible — resolvers fail over automatically.
Do more nameservers mean better security? Not by themselves. NS count is about availability, not authentication — it protects against outage, not against spoofing or hijacking. In our data 10.1% of domains list four records and 0.6% list eight, mostly reflecting their DNS provider’s standard assignment rather than a security decision. Integrity protections like DNSSEC and registrar locks are separate controls.
How do I check how many nameservers my domain has? Your registrar’s control panel lists them, or any public DNS lookup tool will show your NS records in seconds. If you see one record, adding a second is usually free and takes minutes — virtually every registrar and DNS service includes redundant nameservers by default. If you see two, the follow-up question is whether they sit on genuinely separate infrastructure.
How does a domain end up with only one nameserver? Almost always by accident, not design. The most common routes are self-hosted DNS that was never replicated, a secondary nameserver deleted during a migration and never replaced, or a hosting account that lapsed and took the secondary with it. In the August 2026 census, 290,673 domains were in this state — roughly one in 1,296 — and the distribution strongly suggests most of them drifted there rather than being deliberately configured that way.
Does this affect my email deliverability? Yes, in the failure case. When your sole nameserver goes down, incoming mail cannot look up your MX records. Sending servers will queue and retry for several days before bouncing — which means you can miss critical emails during a nameserver outage without knowing it until senders start getting bouncebacks days later.
What this means
For IT managers and security teams, a single-nameserver domain is one of the clearest and most fixable availability risks in your portfolio. There is no ambiguity: a domain with one NS record has exactly one point of failure for everything attached to it — the website, inbound mail, certificate renewals, API endpoints, and every third-party service that verifies the domain by DNS. The fix is free at virtually every provider, and the failure mode when it goes wrong is total. If any domain in your portfolio shows one NS record in a lookup, adding a second nameserver should be treated as a same-week action item.
The broader picture from this data is that the internet has settled at the floor of DNS redundancy. Over half of all graded domains run on exactly two nameservers — the minimum the protocol has required since 1987. That is generally acceptable if those two nameservers sit on genuinely independent infrastructure, but the data cannot confirm that. For business owners managing domains at a registrar that provides only two default nameservers, the question worth asking is whether those two servers share the same network, data centre, or upstream provider. Paper redundancy — two names, one real failure domain — is a common outcome from bundled DNS services that nobody audited.
For organisations with large domain portfolios, the 1-in-1,296 rate of single-NS domains means a portfolio of 1,300 domains statistically contains at least one nameserver single point of failure. A domain audit that includes NS record counts as a basic check would surface these quickly. Given that the cost of adding a second nameserver is typically zero and the downside of missing it is a complete domain outage, this is one of the highest-value, lowest-cost items on any DNS hygiene checklist.
Data to cite
- “290,673 domains in the August 2026 census run on a single nameserver — a complete single point of failure for the website, email, and every DNS-dependent service.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “56.1% of the 376.9 million graded domains run on exactly two nameserver records — the protocol minimum since 1987.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “Only 17.5% of graded domains list three or more nameservers, meaning fewer than one in five domains have any margin beyond the bare minimum.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “A domain with one nameserver faces simultaneous failure of its website, inbound email, certificate renewals, and every DNS-verified service when that server goes down.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “10.1% of domains list exactly four nameservers — a count characteristic of large managed-DNS platforms rather than individual configuration choices.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “2.0% of graded domains — 7,201,091 — list five or more nameservers, with the maximum observed being 192 NS records held by 14 domains.” — defaults.exposed August 2026 Domain Security Census (432M domains)
See where your own domain stands
A second nameserver is the cheapest resilience upgrade on the internet — for most domains it is free and already included in what you pay your registrar. Our census grades real, live domains across externally observable security checks, and most of what a failing domain is missing costs nothing to fix; the barrier is almost never money, it’s that nobody told the owner it mattered. You can check your domain privately and free.
Check your domain free at defaults.exposed — find out immediately how many nameservers your domain lists and whether your DNS redundancy is at the floor, above it, or dangerously below it. Takes 30 seconds. No account needed.
Read the flagship census report: The State of Domain Security 2026 →
How to cite this report
Press / blog: defaults.exposed (2026). Single-Nameserver Domains: One Record from Oblivion. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/one-nameserver-from-oblivion
Academic: defaults.exposed. (2026, August 18). Single-Nameserver Domains: One Record from Oblivion. In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/one-nameserver-from-oblivion
In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=376,928,781)
About the defaults.exposed August 2026 Census
The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.
Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026
Aggregate data only. Data stored and processed in the EU.