Support Library
SRV Records (Enterprise Use Cases)
SRV records publish service endpoint priority, weight, and port for protocol-aware clients.
What It Is
SRV records publish service endpoint priority, weight, and port for protocol-aware clients.
Advanced Use Cases
Kerberos, SIP, and LDAP discovery with controlled failover behaviors.
Common Misconfigurations
Broken target hostnames, bad priority logic, and missing target A/AAAA records.
Security Implications
Misconfigured SRV can break auth flows or push clients to unsafe fallback paths.
Validation Examples
Query service labels and confirm targets resolve and fail over in expected order.
How DNS Panopticon Detects This
- Relevant checks: Delegation integrity, resolver consistency, DNSSEC health, and suspicious record-pattern checks.
- Severity mapping: Informational, medium/high, or critical based on exploitability and user impact.
- Score impact: Reliability and security scoring dimensions are reduced according to blast radius.
- Related findings users will see: NS drift, validation failure, orphaned CNAMEs, wildcard exposure, and policy misconfiguration alerts.
Operator Checklist
- Verify behavior from at least two public resolvers and one resolver inside your own network before making changes.
- Make one change at a time, capture before/after query output, and wait for TTL windows to clear so you can confirm impact.
- Document the root cause and the final fix in your runbook to shorten future incidents.