DNS Resolution
One question from your laptop, a walk from the root down by the resolver, and caches at every level that decide what you see.
An interactive Networking lesson: 21 steps, about 34 minutes, on a live simulation in your browser.
You type shop.example into a browser on laptop. Nothing on the network can use that. Routers forward by IP address, and the shop's server, web, is 198.51.100.10. Something has to turn the name into the number first. That something is DNS.
Watch what the laptop does. It sends one small question, A? shop.example ("what is the IPv4 address for this name?"), to a server called a recursive resolver: here resolver, run by the ISP. Then it waits.
What you will learn
One question, one answer
- A name is not an address: Your machine does not resolve names. It asks one question of a recursive resolver and waits for one answer.
- One packet each way: DNS rides on UDP: one packet out, one packet back, and the asker's own timer is the only reliability.
- Reading dig
Root, TLD, authoritative
- An empty resolver: Resolution walks the name from right to left: root, then TLD, then the domain's own server. Each level knows only who is in charge of the next.
- Referrals, and dig +trace: A referral is a server saying 'not mine, ask this name server', with the address attached. A resolver follows referrals until someone authoritative answers.
Caches and TTLs
- Ask again two minutes later: A TTL is permission to reuse an answer for that many seconds. Caches count it down, and at zero they must ask again.
- The TTL runs out: Each level is cached on its own clock. Answers expire in minutes and referrals in days, so most lookups reach only the last server.
- The laptop caches too: Between a program and the authoritative server sit several caches: browser, operating system, resolver. Each holds its own copy with its own countdown.
Record types
- A zone is a table of records: A DNS question is a name plus a type. The same name can hold an A, an AAAA, an MX and a TXT record, and each is asked for separately.
- CNAME: follow the alias: A CNAME says 'the answer is whatever that other name has'. The resolver follows the chain, across zones if it must, before it replies.
- Drill: ask for one type
When resolution fails
- Break it: a name that is not there: NXDOMAIN is an authoritative no: the zone's own server says the name does not exist. Fix the name or create the record.
- Break it: the authority is down: SERVFAIL is the resolver saying 'I could not get an answer'. The fault is in the zone's name servers or the path to them, not in the name.
- Nobody to ask: A DNS timeout means your question got no answer at all. The fault is between you and your resolver, not in the name you asked for.
- Three failures, three places to look
Changing a record
- Move the shop: DNS does not propagate. A change is live on the authoritative server at once, and every cache keeps its old copy until that copy's TTL expires.
- The stale answer expires
- Roll back, and flush: You can flush the caches you own. For everyone else's, your only tool is the TTL you chose before the change.
- Drill: ask the source
Recap & playground
- Cheat sheet
- Playground