What Is DNS and How It Works
SkillVeris Team
Cloud & Security Team

DNS (Domain Name System) translates human-friendly domain names like example.com into the numeric IP addresses computers use to find each other.
In this guide, you'll learn:
- A DNS lookup walks a chain of resolvers — recursive resolver, root, TLD, and authoritative servers — usually in a few milliseconds.
- Caching at every layer, governed by TTL values, is what keeps DNS fast and keeps the internet from melting under load.
- Record types like A, AAAA, CNAME, MX, and TXT each answer a different question about a domain.
- Tools like dig, nslookup, and host let you inspect exactly what DNS is returning when something breaks.
1What Is DNS?
DNS, the Domain Name System, is the service that translates human-readable domain names such as skillveris.com into the numeric IP addresses that computers use to route traffic. Every time you visit a website, your device quietly asks DNS 'what is the address for this name?' before it can connect.
Think of it as the internet's phone book. People remember names; machines need numbers. DNS bridges that gap automatically, billions of times a second, so you never have to memorise something like 93.184.216.34 to reach a site.
2Why DNS Matters
Without DNS the modern web would be almost unusable — you would need to know the raw IP address of every service you wanted to reach, and those addresses change often as sites move between servers and cloud providers.
- Human usability: names are easy to remember, share, and brand; IP addresses are not.
- Flexibility: a site can change hosting or IP without users noticing, because only the DNS record updates.
- Load distribution: one name can map to many servers, spreading traffic across regions.
- Service discovery: records like MX and SRV tell clients where email and other services live.
🔑Key Idea
DNS adds a layer of indirection between names and addresses. That indirection is what lets the internet stay flexible while remaining easy for humans to navigate.
3How a DNS Lookup Works
A DNS lookup is a relay race between several servers, each responsible for a smaller piece of the name. It usually finishes in a few milliseconds because most answers are cached along the way.
- Your device asks a recursive resolver (often run by your ISP or a public service like 1.1.1.1).
- The resolver asks a root server, which points it to the correct TLD server (.com, .org, and so on).
- The TLD server points to the authoritative name server for the specific domain.
- The authoritative server returns the final answer — the IP address — which the resolver caches and hands back to you.
Recursive vs Authoritative
A recursive resolver does the legwork of chasing down the answer on your behalf. An authoritative server is the source of truth for a particular domain and gives the definitive record. Knowing which is which makes debugging far easier.
4Common DNS Record Types
DNS stores different kinds of records, each answering a specific question about a domain. Learning the handful you meet daily covers almost everything you will configure.
- A = maps a name to an IPv4 address.
- AAAA = maps a name to an IPv6 address.
- CNAME = an alias pointing one name at another name.
- MX = tells senders which mail servers accept email for the domain.
- TXT = free-form text, used for SPF, DKIM, and domain verification.
- NS = lists the authoritative name servers for the domain.
💡Pro Tip
A CNAME cannot coexist with other records on the same name, and you cannot put a CNAME at the root of a domain. Use an A record or your provider's ALIAS/flattening feature for the apex.
5TTL and Caching
Caching is what keeps DNS fast and stops the root servers from being overwhelmed. Every record carries a TTL (time to live) that tells resolvers how long they may keep the answer before asking again.
A short TTL like 300 seconds means changes propagate quickly but resolvers query more often. A long TTL like 86400 seconds means fewer queries but slower propagation when you move a site. Teams often lower the TTL a day before a planned migration, then raise it again afterward.
⚠️Watch Out
Because of caching, a DNS change is not instant. Old answers can linger for the length of the previous TTL, so plan record changes ahead of time rather than expecting them to take effect immediately.
6Debugging DNS Problems
When a site 'won't load' the cause is often DNS, and a couple of command-line tools reveal exactly what is being returned.
- dig example.com A # show the IPv4 address records
- dig example.com MX +short # concise mail server list
- dig @1.1.1.1 example.com # query a specific resolver directly
- nslookup example.com # simple cross-platform lookup
- host example.com # quick summary of common records
Reading the Answer
The ANSWER section of a dig response shows the records returned and their remaining TTL. If you query the authoritative server directly and see the new value, but a public resolver still shows the old one, you are simply waiting on a cache to expire.
7DNS and Security
DNS was designed in an era of implicit trust, so security was bolted on later. The original protocol sends queries in plain text and does not verify that an answer is genuine, which opens the door to spoofing and eavesdropping.
- DNSSEC: cryptographically signs records so resolvers can verify they were not tampered with.
- DNS over HTTPS (DoH): encrypts queries inside normal HTTPS traffic for privacy.
- DNS over TLS (DoT): encrypts queries over a dedicated TLS connection.
- Cache poisoning: an attack where a resolver is tricked into storing a forged record — mitigated by DNSSEC and source-port randomisation.
8DNS Best Practices
A few habits keep your DNS reliable and easy to manage as your services grow.
- Use at least two name servers, ideally in different networks, so one outage does not take you offline.
- Keep TTLs moderate for stable records and lower them temporarily before planned migrations.
- Document what each record is for — stray TXT and CNAME entries accumulate quickly.
- Enable DNSSEC where your registrar supports it to protect record integrity.
- Monitor expiry dates for both the domain and its certificates; a lapsed domain is an instant outage.
9Common Mistakes to Avoid
Most DNS incidents come from a small set of avoidable errors rather than anything exotic.
- Expecting changes to be instant and forgetting the old TTL is still cached.
- Placing a CNAME at the domain apex, which is invalid — use an A or ALIAS record instead.
- Leaving a dangling CNAME pointing at a decommissioned service, a subdomain-takeover risk.
- Setting a TTL so high that an emergency change takes a full day to propagate.
⚠️Watch Out
A dangling CNAME that points to a cloud resource you no longer own can be claimed by an attacker. Remove records the moment the service behind them is retired.
10Key Takeaways
The essentials of DNS come down to a few durable ideas.
- DNS turns domain names into IP addresses so people use names while machines use numbers.
- Resolution walks a chain: recursive resolver → root → TLD → authoritative server.
- TTL-driven caching makes DNS fast but means changes take time to propagate.
- Record types (A, AAAA, CNAME, MX, TXT, NS) each answer a different question.
- Use dig or nslookup to debug, and DNSSEC/DoH to harden a protocol that shipped without security.
11Frequently Asked Questions
Q: How long does a DNS change take to propagate? A: It depends on the previous record's TTL. Resolvers keep the old answer until that timer expires, so a change with a 3600-second TTL can take up to an hour to be seen everywhere, sometimes longer for stubborn caches.
Q: What is the difference between an A record and a CNAME? A: An A record maps a name directly to an IPv4 address. A CNAME maps a name to another name, acting as an alias. Use A records for apex domains and CNAMEs to point subdomains at a canonical hostname.
Q: What is a recursive resolver? A: It is the server that does the work of finding an answer for you, querying the root, TLD, and authoritative servers in turn and caching the result. Public examples include 1.1.1.1 and 8.8.8.8.
Q: Is DNS encrypted? A: Traditional DNS is not — queries travel in plain text. DNS over HTTPS (DoH) and DNS over TLS (DoT) add encryption for privacy, while DNSSEC adds integrity so answers cannot be forged.
Related Reading
Get The Print Version
Download a PDF of this article for offline reading.
About the Publisher
SkillVeris Team
Cloud & Security Team
Our cloud and security experts break down complex infrastructure topics into practical, beginner-friendly guides.
View all postsRelated Posts
Never miss an update
Get the latest tutorials and guides delivered to your inbox.
No spam. Unsubscribe anytime.