Skip to main content
A record set can include failover health-check metadata. Health state is combined with routing selection so unavailable resource records can leave the eligible result set.

Check settings

Design failover

1

Define health precisely

Probe a path or port that reflects whether the endpoint can serve real traffic, not merely whether a process accepts a socket.
2

Mark primary and backup records

Set per-record backup metadata and use a picker chain that prefers eligible primary values.
3

Choose TTL and timing

Resolver caches can retain a previously healthy answer until its TTL expires. Set TTL, frequency, and timeout from the recovery objective and expected transient failures.
4

Test failure and recovery

Fail a staging endpoint, query multiple times through a resolver, and confirm it leaves and later rejoins the eligible set.
Decide the all-endpoints-down behavior before production. DNS cannot create a healthy destination; an overly strict configuration can produce no eligible answer.