The Domain Name System (DNS) is the internet's phone book. Computers talk to each other by IP address, but people use names such as example.com; DNS turns one into the other, and does much more besides: it also says where a domain's mail goes and carries the records that prove who may send email for it.
What happens when you open a website
- Your browser and operating system check their caches. If the name was looked up recently, the answer is already there and nothing else happens.
- The stub resolver asks a recursive resolver, usually run by your ISP, your router or a public service. The recursive resolver does the legwork on your behalf.
- The recursive resolver asks a root server, which does not know the answer but knows who handles
.com. - It asks the
.comTLD servers, which do not knowexample.combut know its authoritative name servers. - It asks the authoritative server, which holds the real records and answers: "
example.comis93.184.216.34". - The answer travels back to your device and is cached along the way, so the next lookup is fast.
The whole chain usually takes tens of milliseconds, and most lookups are answered from a cache.
Record types
| Type | Purpose | Example |
|---|---|---|
A |
Maps a name to an IPv4 address | example.com. 300 IN A 93.184.216.34 |
AAAA |
Maps a name to an IPv6 address | example.com. 300 IN AAAA 2001:db8::1 |
CNAME |
Makes one name an alias of another name | www.example.com. 300 IN CNAME example.com. |
MX |
Names the mail servers for the domain, with a priority (lower is tried first) | example.com. 3600 IN MX 10 mail.example.com. |
TXT |
Free text, used for SPF, DKIM, DMARC and ownership checks | example.com. 3600 IN TXT "v=spf1 -all" |
NS |
Lists the name servers responsible for the domain | example.com. 86400 IN NS ns1.example.net. |
SOA |
Start of authority: the primary server, contact and zone timers | |
PTR |
Reverse lookup: maps an IP address back to a name | 34.216.184.93.in-addr.arpa. IN PTR example.com. |
CAA |
Which certificate authorities may issue certificates for the domain | example.com. IN CAA 0 issue "letsencrypt.org" |
Look up any of these with the DNS Record Lookup, or find a name from an address with the Reverse DNS Lookup.
TTL and caching
Every record has a TTL (time to live) in seconds, which tells caches how long they may reuse the answer. A TTL of 300 means five minutes; 86400 means a day. This is why DNS changes seem to "propagate": nothing is pushed out, but old copies stay in caches until their TTL runs out. Before a planned change, lower the TTL a day or two ahead, make the change, then raise it again. Watch a change spread with the DNS Propagation Checker.
Why DNS matters for security
- Email authentication lives in DNS: SPF, DKIM and DMARC are all TXT records. See How Email Authentication Works: SPF, DKIM and DMARC.
- Certificate issuance often proves domain ownership by asking you to publish a DNS record.
- Spoofing and hijacking. Plain DNS is unencrypted and can be tampered with. DNSSEC signs answers so tampering is detectable, and DNS over HTTPS or TLS encrypts the lookup from your device.
- Dangling records. A
CNAMEthat still points at a service you deleted can be claimed by someone else ("subdomain takeover"). Remove records you no longer use.
Common problems
- A CNAME at the bare domain. The root of a domain (
example.com) cannot be aCNAMEbecause it must also holdNSandSOArecords; useA/AAAArecords or your DNS provider's alias feature. - Forgetting the trailing dot in zone files:
mail.example.comis read asmail.example.com.example.com.; writemail.example.com.. - Two TXT records for SPF. A domain must have exactly one SPF record.
- Expecting instant changes. Cached answers last until their TTL ends.