What is DNS and how does it work?

Computers find each other with IP addresses. People remember names. The Domain Name System, DNS, is the service that translates one into the other: you type example.com, and DNS returns the address your browser needs to connect.
It is often called the phone book of the internet. A closer picture is a chain of directories, where each one knows only who to ask next. That design is what lets DNS cover the whole internet with no single database of every name.
Try it as you read: the DNS Lookup tool shows the live records for any domain.
What happens when you type a name
Your device does not do the searching itself. It hands the question to a resolver, a server whose job is to find the answer. By default that is one run by your internet provider. The resolver then works through the chain.
- Your device asks the resolver for the address of
example.com. - The resolver asks a root server. The root does not know the answer, but it knows which servers handle names ending in
.comand replies with their addresses. - The resolver asks a
.comserver. It does not know the final answer either, but it knows which name servers are responsible forexample.com. - The resolver asks the
example.comname server. This is the authoritative server. It holds the actual records and returns the address. - The resolver replies to your device and keeps a copy of the answer.
All of this normally takes a fraction of a second. Then your browser connects to the address and loads the page.
Why it is fast: caching
The full chain only runs when nobody nearby already knows the answer. Every DNS record carries a time to live, or TTL, measured in seconds. It tells resolvers how long they may reuse the answer before asking again.
Answers are cached at several levels: in your browser, in your operating system, in your router, and in the resolver. For a popular site, the resolver almost always has a fresh copy and can reply at once.
Caching is also why DNS changes are not instant. If a record has a TTL of one hour, resolvers that fetched it a minute before you changed it will keep serving the old value for another 59 minutes. People call this “propagation”, but nothing is being pushed out. Old copies are simply expiring. Lower the TTL a day ahead of a planned change and the switch will be quick.
The parts of a name
DNS names are read from right to left, from general to specific:
www.example.com
comis the top-level domain.exampleis the domain registered under it.wwwis a name the owner ofexample.comcreated.
Each dot marks a point where responsibility can be handed to someone else. The root delegates com to its operator. That operator delegates example.com to whoever registered it. The owner can then create any names underneath.
The root itself is served by 13 named servers, lettered A through M, each of which is really a large group of machines spread around the world. They are listed on IANA’s root servers page.
Common record types
A domain holds different kinds of records for different purposes. These are the ones you will meet most often.
| Type | What it holds | Example |
|---|---|---|
A |
The IPv4 address for a name | 192.0.2.10 |
AAAA |
The IPv6 address for a name | 2001:db8::10 |
CNAME |
An alias that points one name at another name | www points to example.com |
MX |
The mail servers for a domain, each with a priority | 10 mail.example.com |
TXT |
Free text, used mostly for email security and ownership checks | v=spf1 include:_spf.example.com ~all |
NS |
The authoritative name servers for the domain | ns1.example.net |
PTR |
The reverse: a name for an IP address | mail.example.com |
A few notes that save trouble:
- A lower
MXnumber means higher priority. Mail is delivered to the lowest number first. TXTrecords are how services confirm you own a domain, and how SPF, DKIM, and DMARC tell other mail servers which senders to trust.- A
CNAMEcannot sit alongside other records for the same name, which is why it is not used at the bare domain.
You can query each type with the DNS Lookup tool.
Reverse DNS
A normal lookup goes from name to address. A reverse lookup goes from address to name, using PTR records.
The owner of the address block controls these, which usually means the internet provider or hosting company rather than the owner of the domain. Reverse DNS matters most for email: many mail servers distrust messages from an address with no matching name. Check any address with the Reverse DNS tool.
Which resolver are you using?
Unless you have changed it, your devices use the resolver your router tells them to, and the router uses your provider’s.
You can choose a different one. Several organizations run free public resolvers, including Cloudflare (1.1.1.1), Google (8.8.8.8), and Quad9 (9.9.9.9). People switch for speed, for reliability when the provider’s resolver has problems, or for filtering options some of them offer.
You can set a resolver on a single device or in your router, where it applies to everything on the network.
Changing your resolver changes who answers your lookups. It does not change your IP address or hide your traffic from your provider. See how to change or hide your IP address.
Privacy and security
Traditional DNS is not encrypted. Lookups are sent in the clear, so your provider and anyone on the path can see the names you ask for, even when the sites themselves use HTTPS.
Encrypted DNS fixes that part. DNS over TLS (RFC 7858) and DNS over HTTPS (RFC 8484) wrap lookups in encryption between you and the resolver. Current browsers and operating systems support them, sometimes under a name like “Secure DNS” or “Private DNS”. The resolver still sees your queries, so you are choosing who to trust with them.
The lookup tools on this site use DNS over HTTPS from your browser. Queries go straight from you to the resolver and are not stored here.
DNSSEC protects the answers. It lets a resolver verify, with digital signatures, that a record came from the real owner of the domain and was not altered. It does not encrypt anything. It only proves authenticity. Not every domain has it enabled. An introduction is in RFC 4033.
When DNS goes wrong
DNS problems tend to look like “the internet is down” even when the connection is fine. Typical signs: sites fail by name with an error like “server not found”, while apps that are already connected keep working.
Things to try, in order:
- Check another site. If only one name fails, the problem is likely with that domain.
- Look up the name with the DNS Lookup tool. If it returns an answer here but not on your device, your local cache or resolver is the issue.
- Clear your device’s DNS cache. On Windows, run
ipconfig /flushdnsin Command Prompt. On macOS, runsudo killall -HUP mDNSResponderin Terminal. Restarting the device does the same. - Restart the router, which clears its cache too.
- Try a different resolver to see whether your provider’s is at fault.
Key points
- DNS translates names into IP addresses through a chain: root, top-level domain, then the domain’s own servers.
- A resolver does the work and caches the answers. The TTL sets how long.
- DNS changes appear slow because old cached answers have to expire.
- Different record types serve different jobs:
AandAAAAfor addresses,MXfor mail,TXTfor verification. - Encrypted DNS hides lookups from the network. DNSSEC proves answers are genuine.