The internet’s phone book
Computers talk to each other with IP addresses like 93.184.216.34, but people remember names like www.example.com. The Domain Name System (DNS) translates names into addresses. No single server knows everything, so the work is split into a hierarchy.
The cast
| Server | What it knows |
|---|---|
| Recursive resolver | Does the legwork for you and caches answers. Run by your ISP, school or a public service. |
| Root server | Who runs each top-level domain (.com, .org, .in…). |
| TLD server | Which name servers handle each domain under that TLD (example.com). |
| Authoritative server | The real records of the domain (A, AAAA, MX, CNAME…). |
A cold lookup
- The browser asks the resolver: IP of www.example.com?
- The resolver asks a root server and gets a referral to the .com servers.
- It asks the .com TLD server and gets a referral to example.com’s name server.
- It asks the authoritative server and receives the A record.
- The resolver caches the record and returns the IP to the browser.
That is 8 messages. The browser can now open a connection to the address using the TCP handshake.
Caching and TTL
Every record carries a TTL (time to live) in seconds. Resolvers and browsers reuse a cached answer until the TTL expires. A cached lookup needs just 2 messages (question and answer), which is why DNS rarely slows page loads. Short TTLs let a site change its servers quickly. Long TTLs reduce load.
Common record types
- A / AAAA: name → IPv4 / IPv6 address
- CNAME: one name is an alias of another
- MX: mail servers for the domain
- NS: which servers are authoritative
- TXT: free text, often used for e-mail and domain verification
DNS usually runs over UDP on port 53, and falls back to TCP for large answers. In the OSI/TCP-IP model it is an application-layer protocol.
Code
import socket
# Ask the operating system's resolver, exactly as a browser would
print(socket.gethostbyname('www.example.com'))
print(socket.getaddrinfo('www.example.com', 443)[0][4])
Common mistakes
- Thinking the root server knows the IP address. It only knows who to ask next.
- Mixing up the recursive resolver (works for you) with the authoritative server (owns the data).
- Forgetting that cached answers can be stale until the TTL runs out, which is why DNS changes take time to spread.
Complexity at a glance
| Case / operation | Time | Why |
|---|---|---|
| Cold lookup | 8 messages | Browser → resolver, then 3 query/reply pairs to root, TLD and authoritative servers, then the reply. |
| Cached lookup | 2 messages | The resolver answers from its cache until the TTL expires. |
| Extra space | One cache entry per name and record type |
Quick check
Test yourself — pick an answer to see if you got it.
1. What does the DNS root server return when asked for www.example.com?
Root servers only know who runs each top-level domain, so they point the resolver to the right TLD servers.
2. Which server holds the actual A record for example.com?
The authoritative server for the zone is the source of truth for its records.
3. Why is the second visit to a website usually faster to resolve?
Caching avoids the extra queries until the record's time-to-live runs out.
4. Which DNS record type maps a name to an IPv4 address?
A = IPv4 address, AAAA = IPv6 address, CNAME = alias, MX = mail server, NS = name server.