Computers connect to IP addresses; people remember names. The Domain Name System translates between them — billions of times a second, mostly from caches, in a few milliseconds.
The players
- Stub resolver: the small DNS client in your operating system or browser.
- Recursive resolver: a server that does the work of finding answers — run by your ISP, or a public service such as 1.1.1.1 or 8.8.8.8.
- Root servers: know where to find each top-level domain.
- TLD servers: for
.com,.si,.trand so on; they know which name servers are responsible for each domain. - Authoritative name servers: hold a domain’s actual records.
A lookup, step by step
When you open www.example.com and nothing is cached:
- Your device asks its recursive resolver for the A (IPv4) and AAAA (IPv6) records of
www.example.com. - The resolver asks a root server, which replies with the servers for
.com. - It asks a .com server, which replies with the name servers for
example.com(its NS records). - It asks one of example.com’s name servers, which returns the address.
- The resolver returns the answer to you — and caches it.
Caching and TTL
Every record carries a TTL (time to live) in seconds. Resolvers keep an answer for that long before asking again. This is why DNS is fast — and why changes take time: a record with a one-hour TTL may be served from caches for up to an hour after you change it. Lower the TTL before a planned migration.
More than addresses
DNS also tells the world:
- where to deliver email (MX),
- which names are aliases (CNAME),
- which servers may send mail or which certificate authorities may issue certificates (TXT for SPF/DMARC, CAA),
- which servers are authoritative (NS, SOA),
- and, in reverse, which name belongs to an IP address (PTR).
Each has a short guide: A, AAAA, CNAME, MX, TXT, NS.
Security: DNSSEC and encrypted DNS
DNSSEC lets resolvers verify that answers really come from the domain’s owner, using signatures published in DNS. DNS-over-HTTPS and DNS-over-TLS encrypt the connection between you and your resolver so others on the network can’t read or alter your queries. They solve different problems and work well together.
See it live
The DNS lookup queries every common record type live and shows TTLs and DNSSEC status — try it with cloudflare.com.