Skip to content
láb.comLab Notes

Report sheet LN-04 · filed 27 Sept 2026

The Root: the DNS root zone, read as a register

A month-old snapshot that knows it is a month old — and checks itself against the live root on request.

Instrument
labs.llc/root/
Shelf on labs.llc
Live Intelligence · Internet
Bench
Local copy of the build-537 files
Run
27 Sept 2026 · 20:02–20:05 UTC
Controls
IANA Root Zone Database · DNSViz
Evidence
Source lines in the build; timed reads

Aim

The Root turns the DNS root zone into a searchable register: all 1,438 top-level-domain delegations, each with its nameservers, whether it carries a DS record for DNSSEC, its IPv4 and IPv6 glue and its kind — country-code, generic or internationalised — stamped with the zone’s own SOA serial. Two live checks sit beside it: the root’s serial right now, and any TLD’s nameserver set as resolvers answer it.

It is for DNS administrators, domain investors, students and journalists checking who runs a TLD’s servers. We wanted to know how fresh the register was, and how candid the page is when it is not.

Method

Apparatus: what it reads, and where the work happens

Two sources, both named in root/assets/js/root.js (lines 4–12). The register is root-data.js, generated at build time by root/tools/mkroot.py from the zone file published at internic.net; the file it was built from is kept in the tree (2,248,894 bytes). The page loads that data once and filters and pages it in the browser (58–107).

The live wire is Google Public DNS’s JSON interface, called from the browser: an SOA query for the root feeds the watch panel (183–205), and an NS query for a chosen TLD is compared host by host with the snapshot, naming servers ‘new on the wire’ and ‘gone from the wire’ (142–170). The build tool can also diff two zone files — TLDs born and gone, changed server sets, DNSSEC flips — and the page shows that diff when the data carries one (207–227).

It reads

  • The root zone file, internic.net/domain/root.zone, parsed at build time
  • Google Public DNS JSON API, dns.google (live SOA and NS)

Procedure

At 20:02:49 UTC on 27 September 2026 we fetched the page and root-data.js from the local build-537 copy, read the register’s header, and made the two queries the page makes: the live SOA for the root, and the NS set for .im, compared with the register’s entry.

Result

Fig. 11280 × 800

The Root page on labs.llc, titled ROOT: the headline ‘Above every domain sits one file.’, an introduction to the root zone register and its watch, and the buttons ‘Open the register’, ‘The watch’ and ‘Method’.
Fig. 1. The opening screen of labs.llc/root/ at desktop width, captured from the local copy of build 537.

Fig. 2390 × 844

The Root page at phone width: the headline and the introduction to the register in one column, with the first buttons below.
Fig. 2. The same page at phone width.

Table 1 · Run log, 27 September 2026

No.ReadingUTCWhat came back
1Page and registerpage HTTP 200, 41,372 bytes; register HTTP 200, 217,446 bytes
2Register headerserial 2026082702 (parsed 28 Aug); 1,438 TLDs — 248 country-code, 1,039 generic, 151 internationalised; 1,350 with DS; 1,420 with IPv6 glue; no diff
3Live root SOAserial 2026092700 — 30 days on; the panel would say the root has turned
4.im nameservers, live against snapshotthe same four hosts both ways; ‘Live matches the snapshot — 4 servers’

The watch did its job: the register was a month behind, and the page would have said so rather than pass the snapshot off as current. The .im check matched exactly. One detail shapes how to read that match: the answer came through Google’s resolver, whose reply named 83.218.14.53 as the responding server, not from a root server.

Discussion

Two controls: the same job done elsewhere on the web. Each was read on its own page on the date shown, and each is better than The Root at something.

IANA Root Zone Database

Checked .

The authoritative list of every TLD with its type and manager; each links to a page naming the sponsoring organisation, administrative and technical contacts, nameservers, the registry’s website and WHOIS server, and the dates of registration and last update. For .im it named the Isle of Man Government, registered on 11 September 1996.

Where it is better

  • It is the authority, and it names who runs each TLD, with contacts.
  • Registration and update dates, and each registry’s WHOIS server.
  • Always current; the labs register is a periodic snapshot.

Where The Root goes further

  • Filters all 1,438 TLDs by DNSSEC state and kind, with nameserver sets on one page; IANA’s list shows domain, type and manager, with servers a click deeper (root.js 58–107).
  • A live comparison of a TLD’s servers and of the root serial against the snapshot (142–205).

DNSViz

Checked . When fetched it carried a notice that it was in maintenance mode, without access to its back-end database.

Visualises a DNS zone’s status: a graphical analysis of the DNSSEC authentication chain for a name and its resolution path, with a list of configuration errors.

Where it is better

  • Real validation of the chain of trust, errors listed, not just ‘a DS record exists’.
  • Any name at any depth, not only top-level delegations.

Where The Root goes further

  • A whole-root overview: 1,350 of 1,438 TLDs signed and 1,420 with IPv6 glue — figures a per-name analyser does not give.
  • An instant register with no server-side analysis to wait for.

Sources of error: where it falls short

  1. Only as fresh as the last rebuild: 30 days old at test time. The page says so; it cannot fix it.
  2. The diff panel is empty: the data carries no diff, so the born-and-gone machinery is described but not yet visible.
  3. The live check asks one public resolver, not the root servers, so it shows the NS set the resolver returns rather than the root’s own delegation.
  4. No TLD manager, contacts, dates or WHOIS server — IANA has them.
  5. DNSSEC means ‘has a DS record’ only; there is no chain-of-trust validation.

Conclusion

FindingSnapshot 30 days behind the live root — and the watch panel said so.

The Root reads the file most tools never open, keeps it, and stamps every view with the edition it came from. Its best habit is refusing to let that snapshot pose as live: one click sets it against the root as it stands. Our run found a month-old register that said so, and an exact match on .im. For who runs a TLD, go to IANA; for whether DNSSEC validates, DNSViz. For the whole root on one page, this.

Try The Root on labs.llc All ten sheets