Computers find each other by IP addressIP address The number address of a device on the internet, like 203.0.113.10. Computers use it to find each other, the way post uses street addresses. More about IP address →, such as 203.0.113.10. People remember names, such as example.com. The Domain Name System (DNSDNS The internet’s phone book. It turns a name people can remember, like example.com, into the number address computers use to find the server. More about DNS →) is the worldwide directory that turns one into the other.
When you visit a site, your device asks a resolver for the domain’s address. The resolver asks the root servers, then the servers for the ending (such as .com), then the domain’s own nameserversNameserver The server that holds all of a domain’s settings. Whoever runs your nameservers controls where your website and email point. More about Nameserver →, which give the final answer. The answer is cachedCache A saved copy of something, kept so it does not have to be made or fetched again. Like keeping a printed copy instead of reprinting it for every person who asks. More about Cache → for a set time, its TTLTTL How long other computers may remember a domain setting before checking again, in seconds. Short means changes show up faster. More about TTL →.
A lookup, step by step
- Your device checks its own cache. If it looked up the name recently, it already knows the answer.
- It asks a resolver. Usually one run by your internet provider, or a public one such as
1.1.1.1or8.8.8.8. - The resolver asks a root server: “Who handles
.com?” There are 13 named root server addresses, served by hundreds of machines worldwide. - The root replies with the nameservers for
.com. - **The resolver asks a
.comserver:** “Who handlesexample.com?” It replies with that domain’s nameservers, the ones set at the registrarDomain registrar The company you buy and renew your domain name from, and where you choose who handles its settings. More about Domain registrar →. - The resolver asks the domain’s nameserver for the record it needs, for example the A recordA record The line in a domain’s settings that says which server’s address to send visitors to. Like a forwarding address card for your website. More about A record → for
example.com. - The answer comes back with an IP address and a TTL. The resolver caches it and passes it to your device.
This normally takes a few tens of milliseconds, and because almost every step is cached, most lookups skip straight to the end.
Two kinds of DNS server
Almost every DNS question gets clearer once you separate the two jobs:
| Recursive resolver | Authoritative nameserver | |
|---|---|---|
| Job | Finds answers on behalf of devices | Holds the records for specific domains |
| Who runs it | Your internet provider, your company, or a public service such as 1.1.1.1 | Your DNS host: the registrar, Cloudflare, your web host |
| Caches answers | Yes, for each record’s TTL | No, it is the source |
| You change it by | Changing your device or router’s DNS settings | Editing records in your DNS host’s panel |
When a site “doesn’t resolve for me but does for others”, the difference is almost always in a resolver’s cache. When it doesn’t resolve for anyone, the problem is on the authoritative side: the records, the nameservers, or the domain’s registration.
Records, nameservers and the registrar
- Records are the individual answers: A records hold IPv4 addresses, MX recordsMX record The domain setting that tells the world where to deliver your email. More about MX record → name mail servers, and so on. See DNS record types.
- Nameservers are the servers that hold your domain’s records. See what a nameserver is.
- The registrar is where the domain is registered. Its main DNS job is telling the
.comservers which nameservers are in charge of your domain.
Where answers are cached
A single lookup can be answered from any of these, starting with the nearest:
- The browser. Chrome and Firefox keep their own short-lived cache.
- The operating system. Windows, macOS and many Linux systems cache answers.
- The router. Home routers often run a small resolver and cache too.
- The recursive resolver. Your provider’s or a public resolver’s cache, shared by everyone who uses it.
Each layer holds an answer for no longer than its TTL, though some apply their own maximum. When testing a change, ask a resolver directly with dig @1.1.1.1 to skip the layers on your own machine, and flush your DNS cache to clear them.
Why changes are not instant
Every answer carries a TTL, in seconds. A resolver that cached your old A record with a TTL of 3600 keeps using it for up to an hour. That delay, spread across thousands of resolvers worldwide, is what people call DNS propagation.
Security: DNSSEC and encrypted DNS
Plain DNS was designed without security. Two additions fix different problems:
- DNSSEC signs records, so a resolver can check an answer really came from the domain’s nameservers and was not forged. You turn it on at your DNS host, then publish a DS record at your registrar. Done wrong, it makes a domain fail to resolve on validating resolvers, so enable it carefully and only with a provider that manages the keys for you.
- Encrypted DNS (DNS over HTTPSHTTPS The secure version of the web, shown by the padlock. Everything sent between you and the site is scrambled so nobody in between can read or change it. More about HTTPS → or DNS over TLS) hides your lookups from others on your network. Modern browsers and operating systems support it. It protects privacy between your device and the resolver, but does not prove the answers are genuine; that is DNSSEC’s job.
When DNS goes wrong
| Symptom | Usual cause |
|---|---|
| DNS_PROBE_FINISHED_NXDOMAIN everywhere | Domain expired, wrong nameservers, or missing record |
| Old site still showing after a move | Cached answer; wait for the TTL, or check the record was changed |
| Site works but email does not | MX records missing or pointing at the old host |
| Works on mobile data, not on Wi-Fi | The Wi-Fi network’s resolver, or a blocker on it |
SERVFAIL from public resolvers | Broken DNSSEC, or nameservers not answering |
See it for yourself
dig example.com +trace
dig +trace performs the lookup from the root down and prints each step. On Windows, nslookup example.com shows the final answer.
Related
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.



