--- topic: the tiers status: accepted date: 2026-10-03 deciders: jochen reconstructed: false supersedes-in-part: - 0066-public-routing-is-name-agnostic.md - 0151-a-routes-internal-name-is-composed-under-the-node-that-serves-it.md --- # 191. The mesh's resolver holds only the mesh's own names; a public name resolves publicly > **Progressive insight — 2026-10-03.** The first implementation told the mesh's names from public > ones by their spelling — a name ending in the mesh suffix — and this record said so: the Decision > read *"only names under its own suffix"*, and the roster check *"every name the roster carries ends > in the mesh suffix"*. The mesh needs no such test, nor any per-route name: domains are a node's. A > node has **one internal domain**, `.internal`, and every route on it is a name under that domain > (ADR 0151), answered by one wildcard per node; a node has **one or more public domains**, which public > DNS answers. So the mesh's resolver holds the nodes' internal domains and nothing else, and the roster > carries the machines and no routed name. Both sentences now say that; what was decided — a public > name is never given a private answer — is unchanged. ## Context **[ADR 0066](0066-public-routing-is-name-agnostic.md) published every routed name into internal resolution, mesh-wide, at the address of the node that serves it.** The reason was an internal certificate authority in the lab: it validates by connecting to the name it certifies, and a routed public name that nothing inside the mesh resolved could not be certified. [ADR 0151](0151-a-routes-internal-name-is-composed-under-the-node-that-serves-it.md) kept it: *the roster publishes it as itself, once, at the serving node's address.* **So every machine's resolver answered public names with private-network addresses.** On a production mesh on 2026-10-03, each machine's hosts region carried 47 lines of the form `