What Is DNS? A Complete Guide to the Domain Name System

Last Updated: October 2026

Key Takeaways

  • DNS translates domain names (like google.com) into IP addresses that computers can route to.
  • Resolution involves recursive resolvers, root servers, TLD servers, and authoritative name servers.
  • Key record types include A, AAAA, CNAME, MX, TXT, NS, and SOA.
  • DNS responses are cached based on TTL values — this is why changes take time to propagate.
  • DNSSEC, DNS over HTTPS, and DNS over TLS improve DNS security and privacy.
  • Use nslookup or dig to troubleshoot DNS issues from the command line.

The Domain Name System (DNS) is one of the most fundamental technologies underlying the internet. Often described as the "internet's phonebook," DNS translates human-friendly domain names like google.com or computernetworkchecker.com into the numerical IP addresses that computers use to locate and communicate with each other.

Without DNS, you would need to memorize IP addresses for every website you want to visit — imagine typing 142.250.80.46 instead of google.com. DNS makes the internet usable for humans while maintaining the numerical addressing that networks require.

How DNS Resolution Works

When you type a domain name into your browser, a series of behind-the-scenes lookups happen in milliseconds to resolve that name into an IP address. This process is called DNS resolution, and it typically involves four types of DNS servers working together.

Step 1: The DNS Recursive Resolver

Your device first sends the DNS query to a recursive resolver (also called a recursive DNS server). This is usually operated by your ISP, but you can configure your device to use public resolvers like Cloudflare (1.1.1.1) or Google (8.8.8.8). The resolver acts as a middleman — it receives your query and does all the work of tracking down the answer by contacting other DNS servers on your behalf.

Step 2: Root Name Servers

If the resolver does not already have the answer cached, it starts at the top of the DNS hierarchy by querying a root name server. There are 13 sets of root name servers (labeled A through M), each operated by a different organization and distributed globally using anycast routing. The root server does not know the IP address for google.com, but it knows which servers are authoritative for the .com top-level domain and directs the resolver there.

Step 3: TLD (Top-Level Domain) Name Servers

The TLD name server is responsible for all domains under a specific top-level domain, such as .com, .org, .net, or country codes like .ca and .uk. The TLD server does not know the final IP address either, but it knows which name servers are authoritative for the specific domain (e.g., google.com) and refers the resolver there.

Step 4: Authoritative Name Servers

The authoritative name server is the final authority for a domain. It holds the actual DNS records — A records, MX records, TXT records, and so on. The resolver queries the authoritative server for the specific record type requested (e.g., the A record for google.com), receives the answer, and returns it to your device. The resolver also caches the result for the duration specified by the record's TTL (Time to Live).

The Full Journey

To summarize the full DNS resolution path: Your device → Recursive Resolver → Root Server → TLD Server → Authoritative Server → Answer returned to your device. In practice, caching at every level means most queries are resolved in one or two steps rather than the full four-step chain.

DNS Record Types Explained

DNS supports many record types, each serving a different purpose. Here are the most important ones:

A Record (Address)

Maps a domain name to an IPv4 address. This is the most common record type. For example, an A record for example.com might point to 93.184.216.34. A domain can have multiple A records for load balancing or redundancy.

AAAA Record (IPv6 Address)

Maps a domain name to an IPv6 address. Functions identically to an A record but for the newer IPv6 protocol. Example: 2606:2800:220:1:248:1893:25c8:1946.

CNAME Record (Canonical Name)

Creates an alias that points one domain name to another. For example, www.example.com might have a CNAME pointing to example.com, so both names resolve to the same IP address. CNAME records cannot coexist with other record types for the same name, and they should not be used at the zone apex (bare domain).

MX Record (Mail Exchange)

Specifies the mail servers responsible for receiving email for a domain. MX records include a priority value — lower numbers indicate higher priority. For example, a domain might have mx1.example.com with priority 10 and mx2.example.com with priority 20, so mail is delivered to mx1 first, with mx2 as a backup.

TXT Record (Text)

Holds arbitrary text data associated with a domain. TXT records are widely used for email security mechanisms:

  • SPF (Sender Policy Framework) — lists which servers are authorized to send email for the domain.
  • DKIM (DomainKeys Identified Mail) — provides a public key for verifying email signatures.
  • DMARC — defines the domain's email authentication policy.
  • Domain verification — services like Google Workspace and Microsoft 365 use TXT records to verify domain ownership.

NS Record (Name Server)

Specifies which name servers are authoritative for a domain or subdomain. NS records delegate DNS authority. For example, a domain registered at a registrar might have NS records pointing to Cloudflare's name servers if Cloudflare manages its DNS.

SOA Record (Start of Authority)

Contains administrative information about a DNS zone, including the primary name server, the email address of the zone administrator, the zone serial number (used for synchronization), and timing parameters for refresh, retry, expiry, and minimum TTL.

PTR Record (Pointer)

Used for reverse DNS lookups — mapping an IP address back to a domain name. PTR records are stored in the in-addr.arpa (IPv4) or ip6.arpa (IPv6) zones. Reverse DNS is important for email delivery, as many mail servers reject messages from IPs without valid PTR records.

SRV Record (Service)

Specifies the host and port for specific services. SRV records are used by protocols like SIP (VoIP), XMPP (messaging), and LDAP (directory services). They include priority, weight, port, and target fields, enabling sophisticated load balancing and failover for services.

DNS Caching and TTL

DNS caching is essential for performance. Without caching, every website visit would require the full multi-step resolution process, adding hundreds of milliseconds to every page load.

Where DNS Responses Are Cached

  • Browser cache — Your browser maintains its own DNS cache (typically for 1–2 minutes in Chrome). You can view Chrome's DNS cache at chrome://net-internals/#dns.
  • Operating system cache — Your OS maintains a system-wide DNS cache that all applications share. On Windows, the DNS Client service manages this cache.
  • Resolver cache — Your ISP's recursive resolver (or your chosen public resolver) caches responses for all users it serves. This is the most impactful level of caching.

TTL (Time to Live)

Every DNS record includes a TTL value expressed in seconds. The TTL tells caches how long they can store the record before they must query the authoritative server again. Common TTL values are:

  • 300 seconds (5 minutes) — low TTL for records that change frequently or during migrations.
  • 3600 seconds (1 hour) — common default for many DNS providers.
  • 86400 seconds (24 hours) — typical for stable records that rarely change.

When you are about to make DNS changes (e.g., migrating to a new server), it is a best practice to lower the TTL well in advance — sometimes 24–48 hours beforehand — so that caches worldwide expire the old record sooner after the change.

DNS Propagation

DNS propagation refers to the time it takes for updated DNS records to be reflected across all DNS servers worldwide. When you update a record at your authoritative name server, the change does not take effect instantly everywhere because:

  • Recursive resolvers around the world have cached the old record and will continue serving it until the TTL expires.
  • Different resolvers queried the record at different times, so their caches expire at different times.
  • Some resolvers may not strictly honor TTL values, keeping records longer than specified.

Propagation typically takes 5 minutes to 48 hours, depending on the old record's TTL. Records with low TTLs propagate faster. You can use our DNS Lookup tool to check what a specific resolver currently returns for your domain.

Common DNS Providers

You are not locked into your ISP's DNS resolver. Many users switch to public DNS providers for better performance, reliability, or privacy.

Cloudflare DNS (1.1.1.1)

Cloudflare's public resolver is designed for speed and privacy. Cloudflare commits to not logging querier IP addresses and purging all logs within 24 hours. It consistently ranks among the fastest public resolvers globally. Secondary address: 1.0.0.1. IPv6: 2606:4700:4700::1111.

Google Public DNS (8.8.8.8)

Google's public resolver is one of the most widely used DNS services in the world, known for reliability and global reach. It supports DNSSEC validation and DNS over HTTPS/TLS. Secondary address: 8.8.4.4. IPv6: 2001:4860:4860::8888.

OpenDNS (208.67.222.222)

Operated by Cisco, OpenDNS offers optional content filtering and parental controls through its FamilyShield service (208.67.222.123). The standard service provides phishing and botnet protection. Secondary address: 208.67.220.220.

DNS Security

DNS was designed in the 1980s without built-in security, making it vulnerable to several types of attacks. Modern extensions address these vulnerabilities.

DNS Cache Poisoning (DNS Spoofing)

In a cache poisoning attack, an attacker injects fraudulent DNS records into a resolver's cache, redirecting users to malicious websites. For example, an attacker could poison the cache for bank.com to redirect users to a phishing site. This is one of the most dangerous DNS attacks because it affects all users of the poisoned resolver.

DNSSEC (DNS Security Extensions)

DNSSEC adds cryptographic signatures to DNS records. When a resolver receives a DNSSEC-signed response, it can verify that the record was published by the domain owner and has not been modified in transit. DNSSEC creates a chain of trust from the root zone down to individual records. It does not encrypt DNS traffic — it only ensures authenticity and integrity.

DNS over HTTPS (DoH)

DoH encrypts DNS queries by sending them over HTTPS (port 443). Because DoH traffic looks identical to regular web traffic, it is difficult for ISPs and network administrators to monitor or block DNS queries. Major browsers including Chrome, Firefox, and Edge support DoH natively.

DNS over TLS (DoT)

DoT also encrypts DNS queries, but uses a dedicated port (853) with TLS encryption. Unlike DoH, DoT traffic is identifiable at the network level, making it easier for network administrators to manage but also easier to block. Android 9+ supports DoT natively through its "Private DNS" setting.

How to Change Your DNS Server

Switching to a faster or more private DNS resolver is one of the simplest ways to improve your internet experience.

Windows

  1. Open Settings > Network & Internet > Wi-Fi (or Ethernet).
  2. Click Hardware properties or your network name.
  3. Next to DNS server assignment, click Edit.
  4. Change from Automatic to Manual.
  5. Enable IPv4 and enter your preferred DNS (e.g., 1.1.1.1) and alternate DNS (e.g., 1.0.0.1).
  6. Optionally enable IPv6 and enter IPv6 DNS addresses.
  7. Click Save.

macOS

  1. Open System Settings > Network.
  2. Select your active connection and click Details.
  3. Click the DNS tab.
  4. Click the + button and add your preferred DNS servers.
  5. Click OK, then Apply.

Router (All Devices)

Changing DNS at the router level applies to all devices on your network. Log into your router's admin page (usually 192.168.1.1), find the DNS or WAN settings, and replace the ISP-assigned DNS servers with your preferred public DNS addresses. This way, every device — including smart TVs, game consoles, and IoT devices — benefits from the change without individual configuration.

Troubleshooting DNS Issues

DNS problems are one of the most common causes of "website not loading" issues. Here are the essential diagnostic tools and techniques.

nslookup

Available on Windows, macOS, and Linux, nslookup queries a DNS server for a specific record:

  • nslookup example.com — queries the default DNS resolver for A records.
  • nslookup -type=MX example.com — queries for MX (mail) records.
  • nslookup example.com 1.1.1.1 — queries a specific resolver (Cloudflare) instead of the default.

dig

The dig command (available on macOS and Linux; installable on Windows) provides more detailed output:

  • dig example.com — queries for A records with full response details.
  • dig example.com MX — queries for MX records.
  • dig +trace example.com — traces the full resolution path from root servers down.
  • dig @8.8.8.8 example.com — queries Google's DNS specifically.

Flush DNS Cache

If DNS changes are not taking effect on your machine, try flushing the local DNS cache:

  • Windows: Open Command Prompt as Administrator and run ipconfig /flushdns.
  • macOS: Run sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder in Terminal.
  • Linux (systemd-resolved): Run sudo systemd-resolve --flush-caches.
  • Chrome browser: Navigate to chrome://net-internals/#dns and click "Clear host cache."

Common DNS Issues and Fixes

  • "DNS_PROBE_FINISHED_NXDOMAIN" — The domain does not exist in DNS. Check for typos or verify the domain is registered.
  • "Server not found" — Your DNS resolver is unreachable. Try switching to a public resolver like 1.1.1.1 or 8.8.8.8.
  • Website loads for some users but not others — DNS propagation is still in progress. Wait for old cached records to expire.
  • Email not being delivered — Check MX records with nslookup -type=MX yourdomain.com. Verify SPF and DKIM TXT records.

Frequently Asked Questions

What is DNS in simple terms?

DNS (Domain Name System) is the internet's phonebook. It translates human-readable domain names like google.com into IP addresses like 142.250.80.46 that computers use to find and communicate with each other. Without DNS, you would have to memorize numerical IP addresses for every website.

How does DNS resolution work?

Your device sends a query to a recursive resolver, which queries root servers, then TLD servers, then the domain's authoritative name servers. The authoritative server returns the IP address, which the resolver caches and delivers back to your device. This entire process typically takes under 100 milliseconds.

What are the most common DNS record types?

The most common types are: A (IPv4 address), AAAA (IPv6 address), CNAME (alias), MX (mail servers), TXT (text data like SPF/DKIM), NS (name server delegation), and SOA (zone authority information).

Why do DNS changes take time to propagate?

DNS records are cached by resolvers worldwide based on their TTL (Time to Live) value. Until cached copies expire, users may see old data. Propagation typically takes 5 minutes to 48 hours depending on the original TTL. Lowering TTL before making changes helps speed up propagation.

What is the best public DNS server?

It depends on your priorities. Cloudflare (1.1.1.1) is typically the fastest and most privacy-focused. Google (8.8.8.8) offers excellent reliability and global reach. OpenDNS (208.67.222.222) provides optional content filtering. All three support DNSSEC, DoH, and DoT.

What is DNSSEC?

DNSSEC (DNS Security Extensions) adds cryptographic signatures to DNS records, allowing resolvers to verify that responses have not been tampered with. It protects against spoofing and cache poisoning but does not encrypt queries — use DoH or DoT for encryption.

How do I flush my DNS cache?

On Windows: ipconfig /flushdns. On macOS: sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder. On Linux with systemd: sudo systemd-resolve --flush-caches. In Chrome: visit chrome://net-internals/#dns and click "Clear host cache."

What is the difference between DNS over HTTPS and DNS over TLS?

Both encrypt DNS queries. DoH uses HTTPS (port 443) and blends with regular web traffic, making it harder to block. DoT uses a dedicated port (853), making it easier to identify but also easier for administrators to manage. Both effectively prevent eavesdropping on your DNS queries.