Your IP address:
Provider:
...

What is DNS?

DNS, the Domain Name System, is a distributed naming system that helps applications locate network resources. A website name can resolve to IPv4 or IPv6 addresses, while other records direct email or identify authoritative name servers. A domain name does not have to point to just one server.

How a DNS lookup works

Your device normally asks a recursive resolver for an answer. When the resolver lacks a cached answer, it follows DNS delegation from the root through the top-level domain to the authoritative servers responsible for the name. The authoritative server publishes zone data; the resolver returns the relevant answer to the client. The registrar and the DNS operator can be different organisations.

A resolver caches answers for a period related to each record’s time to live, or TTL. It can also cache some negative answers. Consequently, different users may see different results shortly after a record is added or changed. Altering the name servers at the registrar changes delegation; editing an A record on the existing authoritative servers changes zone data. These are distinct operations.

Common DNS records

An A record maps a name to an IPv4 address and an AAAA record maps it to an IPv6 address. MX identifies mail exchangers, NS identifies authoritative name servers, CNAME creates a name alias, and TXT carries text used for purposes such as domain verification or mail authentication. Check the requested record type explicitly: a working MX record says nothing about whether a website is reachable.

When moving a site, updating its address records may be enough. If you also change DNS providers, copy the required MX, TXT and other records before switching delegation. Missing mail records can interrupt delivery even if the website opens. A DNS answer itself only describes naming data; it cannot prove that a server accepts connections, has a valid TLS certificate, or runs a healthy application.

Privacy and DNSSEC

Traditional DNS queries between a client and its resolver are generally unencrypted. DNS over HTTPS and DNS over TLS encrypt that part of the journey, although the selected resolver can still see the queries it processes. DNSSEC authenticates signed DNS data when the trust chain is valid; it does not encrypt the query or make a website safe. These mechanisms solve different problems.

Troubleshooting step by step

If a new site does not open, query its A and AAAA records and identify the authoritative name servers. Compare their answers with those of one or more recursive resolvers. If the authoritative answer is new but the recursive answer is old, caching is a likely explanation. If the authoritative answer is wrong, check the zone and delegation. Record the exact name, record type, resolver and time for support.

After DNS gives the expected address, investigate the next layer separately: network reachability, server response, TLS and application errors. This sequence avoids changing correct DNS records to fix a web-server problem. The protocol foundations are documented in RFC 1034 and RFC 1035.