What is DNS?
The Domain Name System (DNS) is one of the most fundamental systems of the internet. It is a globally distributed, hierarchical directory system that translates human-readable domain names (like provider.tools) into machine-readable IP addresses (like 185.199.108.153) — and vice versa.
Why do we need DNS?
Computers communicate via IP addresses — numerical identifiers like 93.184.216.34 (IPv4) or 2606:2800:220:1:248:1893:25c8:1946 (IPv6). Humans can't easily remember such numbers. DNS solves this problem by acting as a mediator between human and machine language.
Analogy: Think of DNS as the internet's phone book. Instead of memorizing the phone number (IP address) of every person (website), you simply look up the name.
DNS in Numbers
- ~370 million registered domain names worldwide (as of 2025)
- Over 1 trillion DNS queries daily
- 13 root server clusters form the backbone of the entire system
- < 100ms typical DNS resolution time
- 48 hours maximum propagation time for changes
Core Concepts
| Concept | Description |
|---|---|
| Hierarchical | DNS is structured like a tree: Root → TLD → Authoritative Server |
| Distributed | No single server knows all answers — the load is distributed globally |
| Redundant | Each level has multiple servers for fault tolerance |
| Cached | Responses are cached to optimize speed and reduce load |
The DNS Hierarchy
DNS is structured like an inverted tree. Each level has a specific function:
1. Root Zone (the root)
The root zone is the starting point of every DNS resolution. There are 13 root server clusters (named A through M), mirrored worldwide at over 1,500 locations via Anycast. They don't know the answer to your query, but they know where to find the TLD servers.
Root Server (.) ├── .com (TLD) │ ├── google.com (SLD) │ ├── provider.tools (SLD) │ └── ... ├── .de (TLD) │ ├── example.de │ └── ... ├── .org (TLD) └── ...
2. Top-Level Domains (TLDs)
TLDs are the highest level below the root. There are several categories:
- Generic TLDs (gTLDs):
.com,.org,.net,.info,.tools - Country Code TLDs (ccTLDs):
.de(Germany),.at(Austria),.ch(Switzerland),.uk - Sponsored TLDs:
.edu,.gov,.mil - New gTLDs (since 2014):
.app,.dev,.cloud,.shop,.blog
3. Second-Level Domains (SLDs)
The domain you purchase from a registrar: provider.tools, google.com.
4. Subdomains
Further subdivisions to the left of the SLD: mail.provider.tools, www.example.com, api.v2.example.com.
DNS Resolution Process
When you type https://provider.tools into your browser, here's what happens:
Step 1: Browser Cache
The browser checks its own DNS cache. Was this domain resolved recently? If yes → done.
Step 2: Operating System Cache
The OS checks its local DNS cache and the /etc/hosts file (Linux/Mac) or C:\Windows\System32\drivers\etc\hosts (Windows).
Step 3: Recursive Resolver
The configured DNS resolver (usually from your ISP, or e.g. 8.8.8.8 from Google, 1.1.1.1 from Cloudflare) is queried. It has its own cache. If the answer is not cached, recursive resolution begins:
Step 4: Root Server
The resolver asks a root server: "Who is responsible for .tools?" → Answer: IP address of the .tools TLD server.
Step 5: TLD Server
The resolver asks the TLD server: "Who is responsible for provider.tools?" → Answer: IP address of the authoritative nameserver.
Step 6: Authoritative Nameserver
The resolver asks the authoritative nameserver: "What IP does provider.tools have?" → Answer: 185.199.108.153.
Step 7: Response to Client
The resolver caches the response (for the duration defined in the TTL) and returns it to your browser. Your browser can now connect to the web server.
The 4 Participants in DNS Resolution
| Server Type | Role | Example |
|---|---|---|
| Recursive Resolver | Receives query, finds the answer | 8.8.8.8 (Google), 1.1.1.1 (Cloudflare) |
| Root Server | Points to the responsible TLD server | a.root-servers.net |
| TLD Server | Points to the authoritative nameserver | a.nic.tools |
| Authoritative Server | Holds the actual DNS records | ns1.provider.tools |
DNS Caching & TTL
DNS caching is essential for the performance of the entire internet. Without caching, every single DNS query would need to go through the full resolution process — which would overload root servers and massively increase load times.
What is TTL (Time to Live)?
Every DNS record has a TTL value (in seconds) that specifies how long the response may be cached. After the TTL expires, the information is considered stale and must be re-queried.
| TTL Value | Duration | Use Case |
|---|---|---|
300 | 5 minutes | Frequently changed records, failover scenarios |
3600 | 1 hour | Standard for most records |
14400 | 4 hours | Stable records (e.g. MX with fixed mail servers) |
86400 | 24 hours | Very stable records (e.g. NS records) |
604800 | 7 days | Practically immutable records |
Best Practices for TTL
- Before planned changes: Lower TTL to
300(5 min) 2–4 hours in advance → make the change → raise TTL again - For mail servers (MX):
3600to14400— too low can cause delivery issues during cache expiry - For nameservers (NS):
86400or higher — NS changes are rare - For load balancing/failover:
60to300— fast switching required
Cache Levels
- Browser Cache: Chrome, Firefox etc. cache DNS entries (Chrome:
chrome://net-internals/#dns) - OS Cache: Operating system level (Windows:
ipconfig /flushdns, Linux:systemd-resolve --flush-caches, macOS:sudo dscacheutil -flushcache) - Router Cache: Your router often caches DNS responses
- ISP Resolver Cache: Your internet provider caches responses centrally
- Recursive Resolver Cache: Google DNS, Cloudflare etc. have their own caches
Related articles
DNS Record Types — Complete Reference
Detailed reference of all DNS record types: A, AAAA, CNAME, MX, NS, TXT, SOA, PTR, SRV, CAA, DS, DNSKEY, NAPTR, SSHFP and more.
ReadDNS Propagation — Why Changes Take Time
Understanding DNS propagation: Why DNS changes don't take effect immediately, how to speed it up, and how to verify propagation worldwide.
ReadDNSSEC — Securing the Domain Name System
How DNSSEC protects against DNS spoofing and cache poisoning with cryptographic signatures and chain of trust.
Read