Skip to content
ipaddress.si
DNS2 min read

How does DNS work?

From typing a name to getting an address: resolvers, root servers, TLDs, caching and TTLs, in plain language.

By ipaddress.si

Computers connect to IP addresses; people remember names. The Domain Name System translates between them — billions of times a second, mostly from caches, in a few milliseconds.

The players

  • Stub resolver: the small DNS client in your operating system or browser.
  • Recursive resolver: a server that does the work of finding answers — run by your ISP, or a public service such as 1.1.1.1 or 8.8.8.8.
  • Root servers: know where to find each top-level domain.
  • TLD servers: for .com, .si, .tr and so on; they know which name servers are responsible for each domain.
  • Authoritative name servers: hold a domain’s actual records.

A lookup, step by step

When you open www.example.com and nothing is cached:

  1. Your device asks its recursive resolver for the A (IPv4) and AAAA (IPv6) records of www.example.com.
  2. The resolver asks a root server, which replies with the servers for .com.
  3. It asks a .com server, which replies with the name servers for example.com (its NS records).
  4. It asks one of example.com’s name servers, which returns the address.
  5. The resolver returns the answer to you — and caches it.

Caching and TTL

Every record carries a TTL (time to live) in seconds. Resolvers keep an answer for that long before asking again. This is why DNS is fast — and why changes take time: a record with a one-hour TTL may be served from caches for up to an hour after you change it. Lower the TTL before a planned migration.

More than addresses

DNS also tells the world:

  • where to deliver email (MX),
  • which names are aliases (CNAME),
  • which servers may send mail or which certificate authorities may issue certificates (TXT for SPF/DMARC, CAA),
  • which servers are authoritative (NS, SOA),
  • and, in reverse, which name belongs to an IP address (PTR).

Each has a short guide: A, AAAA, CNAME, MX, TXT, NS.

Security: DNSSEC and encrypted DNS

DNSSEC lets resolvers verify that answers really come from the domain’s owner, using signatures published in DNS. DNS-over-HTTPS and DNS-over-TLS encrypt the connection between you and your resolver so others on the network can’t read or alter your queries. They solve different problems and work well together.

See it live

The DNS lookup queries every common record type live and shows TTLs and DNSSEC status — try it with cloudflare.com.

  • Privacy2 min read

    What is CGNAT (carrier-grade NAT)?

    Why your provider may be sharing one public IPv4 address with hundreds of customers, how to tell, and what it breaks.

  • IP addresses2 min read

    Why does my IP address change?

    Dynamic leases, router restarts, mobile networks and IPv6 privacy addresses: the everyday reasons your IP isn't constant.

  • IP addresses2 min read

    Public vs private IP addresses

    Why your laptop's address starts with 192.168 while websites see something else — and what that means for connectivity and privacy.