The established nameserver.
WHAT IT IS
The most widely deployed nameserver, capable of both authoritative and recursive roles.
WHAT IT PROVIDES
Full standards support Views, serving different answers to different clients Dynamic updates DNSSEC signing Extensive control
WHAT IT COSTS
Configuration complexity A history of vulnerabilities requiring prompt patching
WHAT TO SEPARATE
Authoritative and recursive functions, onto different instances.
WHY
Combining them increases exposure and complicates policy.
WHAT TO CONFIGURE CAREFULLY
Which clients may query recursively Which may transfer zones Which may send dynamic updates Rate limiting
WHAT VIEWS SUIT
Serving internal and external answers for the same names.
WHAT TO BE CAREFUL WITH
View configuration errors leaking internal data Zone files edited by hand, which invites syntax errors
WHAT TO USE
Configuration checking tools before reloading.
WHAT TO MONITOR
Query rates, failures, and that reloads succeeded.
WHAT TO PATCH PROMPTLY
It, since vulnerabilities are announced and exploited.