Guides Networking

How DNS Works

How a name becomes an IP address through resolvers, root, TLD and authoritative servers, the record types, TTL and caching, and DNS security basics.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page
On this page

The Domain Name System (DNS) is the internet's phone book. Computers talk to each other by IP address, but people use names such as example.com; DNS turns one into the other, and does much more besides: it also says where a domain's mail goes and carries the records that prove who may send email for it.

What happens when you open a website

  1. Your browser and operating system check their caches. If the name was looked up recently, the answer is already there and nothing else happens.
  2. The stub resolver asks a recursive resolver, usually run by your ISP, your router or a public service. The recursive resolver does the legwork on your behalf.
  3. The recursive resolver asks a root server, which does not know the answer but knows who handles .com.
  4. It asks the .com TLD servers, which do not know example.com but know its authoritative name servers.
  5. It asks the authoritative server, which holds the real records and answers: "example.com is 93.184.216.34".
  6. The answer travels back to your device and is cached along the way, so the next lookup is fast.

The whole chain usually takes tens of milliseconds, and most lookups are answered from a cache.

Record types

Type Purpose Example
A Maps a name to an IPv4 address example.com. 300 IN A 93.184.216.34
AAAA Maps a name to an IPv6 address example.com. 300 IN AAAA 2001:db8::1
CNAME Makes one name an alias of another name www.example.com. 300 IN CNAME example.com.
MX Names the mail servers for the domain, with a priority (lower is tried first) example.com. 3600 IN MX 10 mail.example.com.
TXT Free text, used for SPF, DKIM, DMARC and ownership checks example.com. 3600 IN TXT "v=spf1 -all"
NS Lists the name servers responsible for the domain example.com. 86400 IN NS ns1.example.net.
SOA Start of authority: the primary server, contact and zone timers
PTR Reverse lookup: maps an IP address back to a name 34.216.184.93.in-addr.arpa. IN PTR example.com.
CAA Which certificate authorities may issue certificates for the domain example.com. IN CAA 0 issue "letsencrypt.org"

Look up any of these with the DNS Record Lookup, or find a name from an address with the Reverse DNS Lookup.

TTL and caching

Every record has a TTL (time to live) in seconds, which tells caches how long they may reuse the answer. A TTL of 300 means five minutes; 86400 means a day. This is why DNS changes seem to "propagate": nothing is pushed out, but old copies stay in caches until their TTL runs out. Before a planned change, lower the TTL a day or two ahead, make the change, then raise it again. Watch a change spread with the DNS Propagation Checker.

Why DNS matters for security

  • Email authentication lives in DNS: SPF, DKIM and DMARC are all TXT records. See How Email Authentication Works: SPF, DKIM and DMARC.
  • Certificate issuance often proves domain ownership by asking you to publish a DNS record.
  • Spoofing and hijacking. Plain DNS is unencrypted and can be tampered with. DNSSEC signs answers so tampering is detectable, and DNS over HTTPS or TLS encrypts the lookup from your device.
  • Dangling records. A CNAME that still points at a service you deleted can be claimed by someone else ("subdomain takeover"). Remove records you no longer use.

Common problems

  • A CNAME at the bare domain. The root of a domain (example.com) cannot be a CNAME because it must also hold NS and SOA records; use A/AAAA records or your DNS provider's alias feature.
  • Forgetting the trailing dot in zone files: mail.example.com is read as mail.example.com.example.com.; write mail.example.com..
  • Two TXT records for SPF. A domain must have exactly one SPF record.
  • Expecting instant changes. Cached answers last until their TTL ends.

Try these tools

See also

  • Glossary DNS
    DNS (Domain Name System) is the internet's directory that translates domain names like example.com into IP addresses and holds other.
  • Glossary TTL
    TTL (time to live) is how long, in seconds, a DNS record or cached item may be reused before it must be fetched again.
  • Glossary MX record
    An MX (mail exchanger) record is a DNS record that names the servers that accept email for a domain, with a priority number.
  • Guide How Email Authentication Works: SPF, DKIM and DMARC
    What SPF, DKIM and DMARC each check, what their DNS records look like.

Frequently Asked Questions

Resolvers cache answers for the record's TTL. Until that time passes, some of them keep returning the old value. Lowering the TTL before a planned change shortens the wait.

AdSense Placeholder
Slot: footer_leaderboard