Join our Newsletter — 33% off our NHI Course

SRV Record

An SRV record is a DNS entry that tells clients which server provides a specific service, such as Active Directory logon support. AD relies on these records so workstations can discover domain controllers automatically instead of hardcoding server names or addresses.

How SRV Records Work

SRV records add a service layer to DNS. Instead of pointing clients only to a host name, they publish the service location, port, priority, and weight so software can find the right server for a named function.

That makes SRV records useful when one service can be hosted on several machines or when clients should discover servers automatically. In Active Directory environments, for example, they help workstations locate domain controllers without hardcoded endpoints.

Why SRV Records Matter in Enterprise Networks

SRV records reduce configuration drift and make infrastructure changes less disruptive because the service name stays stable even when back-end hosts change. They also support load distribution and failover by allowing multiple targets with different priority and weight values.

For operators, the value is not only convenience, it is also consistency. A correctly maintained SRV record can hide server churn from clients, while a stale or missing record can break discovery even when the underlying service is healthy.

Common SRV Record Fields and Behavior

An SRV record typically includes a service name, protocol, priority, weight, port, and target host. Priority helps clients choose between multiple servers, while weight lets them spread requests among servers at the same priority.

The target host often has its own A or AAAA record, so SRV lookups usually work as part of a chain of DNS resolution steps. That means the record is only as reliable as the surrounding DNS data, zone management, and delegation path.

Where SRV Records Fail

SRV records fail when the discovery path no longer matches reality. A wrong port, incorrect target name, expired TTL, or missing companion A and AAAA record can make clients connect to the wrong place or fail to connect at all.

They are also sensitive to update discipline. In environments such as directory services, messaging, voice, and federated authentication, an outdated SRV entry can create outages that look like application problems but are really service-discovery problems.

Risk and Threat Considerations

SRV records are a discovery control, so errors or tampering can redirect clients toward the wrong service, disrupt authentication flows, or create an opportunity for traffic interception if users trust DNS answers too much.

Failure mechanism: Attackers or misconfigurations can alter service location data, exploit stale DNS caching, or publish a rogue target that clients accept as authoritative for a service.

Impact: The result can be service outage, failed logon, misrouted traffic, or exposure of clients to malicious infrastructure that impersonates a legitimate endpoint.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 SC-20 — Secure Name/Address Resolution Service (Authoritative Source) SRV records depend on trustworthy DNS name resolution for service discovery.
Recommendation — Protect service-discovery records with trusted DNS resolution and integrity checks.
NIST CSF 2.0 PR.DS-8 — Integrity of Data-at-Rest SRV data in DNS zones must remain accurate to preserve reliable service discovery.
Recommendation — Monitor and protect DNS zone integrity for service-discovery records.
CIS Controls v8 CIS-12 — Network Infrastructure Management SRV records are part of network service publishing and DNS infrastructure management.
Recommendation — Inventory and manage DNS service records as part of network infrastructure control.