Join our Newsletter — 33% off our NHI Course
Architecture & Implementation

SRV Record

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: Architecture & Implementation

An SRV record is a DNS entry that tells clients which server provides a specific service, such as Active Directory logon support. AD relies on these records so workstations can discover domain controllers automatically instead of hardcoding server names or addresses.

How SRV Records Work

SRV records add a service layer to DNS. Instead of pointing clients only to a host name, they publish the service location, port, priority, and weight so software can find the right server for a named function.

That makes SRV records useful when one service can be hosted on several machines or when clients should discover servers automatically. In Active Directory environments, for example, they help workstations locate domain controllers without hardcoded endpoints.

Why SRV Records Matter in Enterprise Networks

SRV records reduce configuration drift and make infrastructure changes less disruptive because the service name stays stable even when back-end hosts change. They also support load distribution and failover by allowing multiple targets with different priority and weight values.

For operators, the value is not only convenience, it is also consistency. A correctly maintained SRV record can hide server churn from clients, while a stale or missing record can break discovery even when the underlying service is healthy.

Common SRV Record Fields and Behavior

An SRV record typically includes a service name, protocol, priority, weight, port, and target host. Priority helps clients choose between multiple servers, while weight lets them spread requests among servers at the same priority.

The target host often has its own A or AAAA record, so SRV lookups usually work as part of a chain of DNS resolution steps. That means the record is only as reliable as the surrounding DNS data, zone management, and delegation path.

Where SRV Records Fail

SRV records fail when the discovery path no longer matches reality. A wrong port, incorrect target name, expired TTL, or missing companion A and AAAA record can make clients connect to the wrong place or fail to connect at all.

They are also sensitive to update discipline. In environments such as directory services, messaging, voice, and federated authentication, an outdated SRV entry can create outages that look like application problems but are really service-discovery problems.

Risk and Threat Considerations

SRV records are a discovery control, so errors or tampering can redirect clients toward the wrong service, disrupt authentication flows, or create an opportunity for traffic interception if users trust DNS answers too much.

Failure mechanism: Attackers or misconfigurations can alter service location data, exploit stale DNS caching, or publish a rogue target that clients accept as authoritative for a service.

Impact: The result can be service outage, failed logon, misrouted traffic, or exposure of clients to malicious infrastructure that impersonates a legitimate endpoint.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5SC-20 — Secure Name/Address Resolution Service (Authoritative Source)SRV records depend on trustworthy DNS name resolution for service discovery.
Recommendation — Protect service-discovery records with trusted DNS resolution and integrity checks.
NIST CSF 2.0PR.DS-8 — Integrity of Data-at-RestSRV data in DNS zones must remain accurate to preserve reliable service discovery.
Recommendation — Monitor and protect DNS zone integrity for service-discovery records.
CIS Controls v8CIS-12 — Network Infrastructure ManagementSRV records are part of network service publishing and DNS infrastructure management.
Recommendation — Inventory and manage DNS service records as part of network infrastructure control.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org