7. SOA RRs
The SOA (Start Of Authority) Resource Record (RR) is the first RR in any standard zone file. It contains information about the zone, including the name of the primary name server for the zone, the email address of the responsible person, and various timers relating to the zone's refresh and retry policies.
7.1. Placement of SOA RRs in authoritative answers
The SOA RR for a zone must be present at the zone apex (the top of the zone). It must not be present at a zone cut, except as the SOA RR for the child zone (which is in the child zone, not the parent zone).
When an authoritative server responds to a query with an authoritative answer, and the answer includes a negative response (NXDOMAIN or NODATA), the authority section of the response must include the SOA RR for the zone that is authoritative for the query. This is used by resolvers to determine the negative caching TTL for the response.
7.2. TTLs on SOA RRs
The TTL of an SOA RR is not used in the same way as the TTL of other RRs. The TTL of an SOA RR is used to determine the minimum TTL for the zone, and is used by resolvers as the default TTL for negative caching.
The TTL of an SOA RR must be the same as the minimum TTL for the zone. That is, the TTL of the SOA RR is the minimum of the TTLs of all the RRs in the zone.
7.3. The SOA MNAME field
The MNAME field of the SOA RR is the name of the primary (master) name server for the zone. This is the server that is the source of the zone's data. The MNAME field is used by secondary (slave) name servers to determine the source of the zone's data for zone transfers (AXFR and IXFR).
The MNAME field should be the name of the primary name server for the zone. It must not be a CNAME or other alias. It must be the name of a host that is a name server for the zone.