How DNS works

DNS turns a name like example.com into the IP address of a server. Here is every step of a lookup, and why caching makes changes take time.

3–5 minutes
Glowing ends of a fibre optic bundle

Computers find each other by IP addressIP address The number address of a device on the internet, like 203.0.113.10. Computers use it to find each other, the way post uses street addresses. More about IP address →, such as 203.0.113.10. People remember names, such as example.com. The Domain Name System (DNSDNS The internet’s phone book. It turns a name people can remember, like example.com, into the number address computers use to find the server. More about DNS →) is the worldwide directory that turns one into the other.

When you visit a site, your device asks a resolver for the domain’s address. The resolver asks the root servers, then the servers for the ending (such as .com), then the domain’s own nameserversNameserver The server that holds all of a domain’s settings. Whoever runs your nameservers controls where your website and email point. More about Nameserver →, which give the final answer. The answer is cachedCache A saved copy of something, kept so it does not have to be made or fetched again. Like keeping a printed copy instead of reprinting it for every person who asks. More about Cache → for a set time, its TTLTTL How long other computers may remember a domain setting before checking again, in seconds. Short means changes show up faster. More about TTL →.

A lookup, step by step

  1. Your device checks its own cache. If it looked up the name recently, it already knows the answer.
  2. It asks a resolver. Usually one run by your internet provider, or a public one such as 1.1.1.1 or 8.8.8.8.
  3. The resolver asks a root server: “Who handles .com?” There are 13 named root server addresses, served by hundreds of machines worldwide.
  4. The root replies with the nameservers for .com.
  5. **The resolver asks a .com server:** “Who handles example.com?” It replies with that domain’s nameservers, the ones set at the registrarDomain registrar The company you buy and renew your domain name from, and where you choose who handles its settings. More about Domain registrar →.
  6. The resolver asks the domain’s nameserver for the record it needs, for example the A recordA record The line in a domain’s settings that says which server’s address to send visitors to. Like a forwarding address card for your website. More about A record → for example.com.
  7. The answer comes back with an IP address and a TTL. The resolver caches it and passes it to your device.

This normally takes a few tens of milliseconds, and because almost every step is cached, most lookups skip straight to the end.

Two kinds of DNS server

Almost every DNS question gets clearer once you separate the two jobs:

Recursive resolverAuthoritative nameserver
JobFinds answers on behalf of devicesHolds the records for specific domains
Who runs itYour internet provider, your company, or a public service such as 1.1.1.1Your DNS host: the registrar, Cloudflare, your web host
Caches answersYes, for each record’s TTLNo, it is the source
You change it byChanging your device or router’s DNS settingsEditing records in your DNS host’s panel

When a site “doesn’t resolve for me but does for others”, the difference is almost always in a resolver’s cache. When it doesn’t resolve for anyone, the problem is on the authoritative side: the records, the nameservers, or the domain’s registration.

Records, nameservers and the registrar

  • Records are the individual answers: A records hold IPv4 addresses, MX recordsMX record The domain setting that tells the world where to deliver your email. More about MX record → name mail servers, and so on. See DNS record types.
  • Nameservers are the servers that hold your domain’s records. See what a nameserver is.
  • The registrar is where the domain is registered. Its main DNS job is telling the .com servers which nameservers are in charge of your domain.

Where answers are cached

A single lookup can be answered from any of these, starting with the nearest:

  1. The browser. Chrome and Firefox keep their own short-lived cache.
  2. The operating system. Windows, macOS and many Linux systems cache answers.
  3. The router. Home routers often run a small resolver and cache too.
  4. The recursive resolver. Your provider’s or a public resolver’s cache, shared by everyone who uses it.

Each layer holds an answer for no longer than its TTL, though some apply their own maximum. When testing a change, ask a resolver directly with dig @1.1.1.1 to skip the layers on your own machine, and flush your DNS cache to clear them.

Why changes are not instant

Every answer carries a TTL, in seconds. A resolver that cached your old A record with a TTL of 3600 keeps using it for up to an hour. That delay, spread across thousands of resolvers worldwide, is what people call DNS propagation.

Security: DNSSEC and encrypted DNS

Plain DNS was designed without security. Two additions fix different problems:

  • DNSSEC signs records, so a resolver can check an answer really came from the domain’s nameservers and was not forged. You turn it on at your DNS host, then publish a DS record at your registrar. Done wrong, it makes a domain fail to resolve on validating resolvers, so enable it carefully and only with a provider that manages the keys for you.
  • Encrypted DNS (DNS over HTTPSHTTPS The secure version of the web, shown by the padlock. Everything sent between you and the site is scrambled so nobody in between can read or change it. More about HTTPS → or DNS over TLS) hides your lookups from others on your network. Modern browsers and operating systems support it. It protects privacy between your device and the resolver, but does not prove the answers are genuine; that is DNSSEC’s job.

When DNS goes wrong

SymptomUsual cause
DNS_PROBE_FINISHED_NXDOMAIN everywhereDomain expired, wrong nameservers, or missing record
Old site still showing after a moveCached answer; wait for the TTL, or check the record was changed
Site works but email does notMX records missing or pointing at the old host
Works on mobile data, not on Wi-FiThe Wi-Fi network’s resolver, or a blocker on it
SERVFAIL from public resolversBroken DNSSEC, or nameservers not answering

See it for yourself

dig example.com +trace

dig +trace performs the lookup from the root down and prints each step. On Windows, nslookup example.com shows the final answer.

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.