How Traffic Manager Works

Azure Traffic Manager enables you to control the distribution of traffic across your application endpoints. An endpoint is any Internet-facing service hosted inside or outside of Azure.

Traffic Manager provides two key benefits:

When a client attempts to connect to a service, it must first resolve the DNS name of the service to an IP address. The client then connects to that IP address to access the service.

The most important point to understand is that Traffic Manager works at the DNS level which is at the Application layer (Layer-7). Traffic Manager uses DNS to direct clients to specific service endpoints based on the rules of the traffic-routing method. Clients connect to the selected endpoint directly. Traffic Manager is not a proxy or a gateway. Traffic Manager does not see the traffic passing between the client and the service.

Traffic Manager uses profiles to control traffic to your cloud services or website endpoints. For more information about profiles, see Manage an Azure Traffic Manager profile.

Traffic Manager example

Contoso Corp have developed a new partner portal. The URL for this portal is The application is hosted in three regions of Azure. To improve availability and maximize global performance, they use Traffic Manager to distribute client traffic to the closest available endpoint.

To achieve this configuration, they complete the following steps:

  1. Deploy three instances of their service. The DNS names of these deployments are '', '', and ''.
  2. Create a Traffic Manager profile, named '', and configure it to use the 'Performance' traffic-routing method across the three endpoints.
  3. Configure their vanity domain name, '', to point to '', using a DNS CNAME record.


Only one Azure [tenant ID] can own a given root traffic manager DNS name. Attempting to use a name that is already in use will display an error. In the following example, the root DNS name is contoso. Also, if a profile is created using a dot-separated name, such as, then is automatically reserved.

Traffic Manager DNS configuration


When using a vanity domain with Azure Traffic Manager, you must use a CNAME to point your vanity domain name to your Traffic Manager domain name. DNS standards don't allow you to create a CNAME at the 'apex' (or root) of a domain. Thus you cannot create a CNAME for '' (sometimes called a 'naked' domain). You can only create a CNAME for a domain under '', such as ''. To work around this limitation, we recommend hosting your DNS domain on Azure DNS and using Alias records to point to your traffic manager profile. Alternatively you can use a simple HTTP redirect to direct requests for '' to an alternative name such as ''.

How clients connect using Traffic Manager

Continuing from the previous example, when a client requests the page, the client performs the following steps to resolve the DNS name and establish a connection:

Connection establishment using Traffic Manager

  1. The client sends a DNS query to its configured recursive DNS service to resolve the name ''. A recursive DNS service, sometimes called a 'local DNS' service, does not host DNS domains directly. Rather, the client off-loads the work of contacting the various authoritative DNS services across the Internet needed to resolve a DNS name.

  2. To resolve the DNS name, the recursive DNS service finds the name servers for the '' domain. It then contacts those name servers to request the '' DNS record. The DNS servers return the CNAME record that points to

  3. Next, the recursive DNS service finds the name servers for the '' domain, which are provided by the Azure Traffic Manager service. It then sends a request for the '' DNS record to those DNS servers.

  4. The Traffic Manager name servers receive the request. They choose an endpoint based on:

  5. The chosen endpoint is returned as another DNS CNAME record. In this case, let us suppose is returned.

  6. Next, the recursive DNS service finds the name servers for the '' domain. It contacts those name servers to request the '' DNS record. A DNS 'A' record containing the IP address of the EU-based service endpoint is returned.

  7. The recursive DNS service consolidates the results and returns a single DNS response to the client.

  8. The client receives the DNS results and connects to the given IP address. The client connects to the application service endpoint directly, not through Traffic Manager. Since it is an HTTPS endpoint, the client performs the necessary SSL/TLS handshake, and then makes an HTTP GET request for the '/login.aspx' page.

Traffic Manager and the DNS cache

The recursive DNS service caches the DNS responses it receives. The DNS resolver on the client device also caches the result. Caching enables subsequent DNS queries to be answered more quickly by using data from the cache rather than querying other name servers. The duration of the cache is determined by the 'time-to-live' (TTL) property of each DNS record. Shorter values result in faster cache expiry and thus more round-trips to the Traffic Manager name servers. Longer values mean that it can take longer to direct traffic away from a failed endpoint. Traffic Manager allows you to configure the TTL used in Traffic Manager DNS responses to be as low as 0 seconds and as high as 2,147,483,647 seconds (the maximum range compliant with RFC-1035), enabling you to choose the value that best balances the needs of your application.


Next steps

Learn more about Traffic Manager endpoint monitoring and automatic failover.

Learn more about Traffic Manager traffic routing methods.