DNS
No machine anywhere holds a list of every name on the internet. A full recursive resolver with nothing cached begins from its root hints, and and on this walk every server it asks either answers or names the servers to ask instead. That referral is not a failure to answer. It is the answer, and following three or four of them is how a name gets found the first time anybody asks for it. Your laptop almost certainly does none of this itself: it runs a stub resolver that hands the question to a recursive resolver and waits.
New to networks? Start here
A message that takes time and may not arrive
A message takes time to travel from one computer to another. Sending it does not establish that it arrived, and receiving one message does not establish that an earlier one arrived first.
Messages may be delayed, lost, duplicated or reordered. A protocol defines how the participants respond to those possibilities. Some machines here model only one of them; the page says which assumptions its result needs.
The machine for this idea on its own is Packet Switching, if you would rather press it than read about it.
A walk from the root, one referral at a time, and what a cache is worth
1 A resolver that knows one thing: where the root is
The resolver is told the root servers when it is installed and knows nothing else. Pick a name and watch it start from there.
2 The root, which knows the top-level domain
The root does not know the address and never did. What it knows is which servers are authoritative for the top-level domain, and it says so.
| zone | asked | said | kind |
|---|---|---|---|
| the root | a.root-servers.net | a.cctld.us | ask them instead |
| us | a.cctld.us | ns1.logicalart.us | ask them instead |
| logicalart.us | ns1.logicalart.us | 203.0.113.10 | the answer |
3 The top-level domain, which knows the authoritative server
Each referral is one step further down the tree, and the tree is the name read backwards. The last server in the chain is the only one that holds the address.
- the name
- logicalart.us
- servers asked
- 3
- the address
- 203.0.113.10
4 The answer, and how long anyone is allowed to keep it
The answer arrives with a time to live, which is a permission rather than a promise: it says how long anybody may keep this before asking again. Ask the same name twice and the second walk is shorter, because the referrals were kept too.
- time to live
- 3600 seconds (60 minutes)
- servers asked the second time
- 0
- queries saved
- 3
These ran in this browser when the page loaded. Each claim, whether it held, and the number behind it.
| claim | held | measured |
|---|---|---|
| a cold recursive resolver starts at the root, which is the one address its hints file gives it | yes | the root -> us -> logicalart.us |
| exactly one of the 3 steps is an answer and the other 2 are referrals | yes | a referral is the mechanism working, not a server failing to answer |
| every referral names the next server, so the walk never stalls | yes | 2 referrals, each naming a server one zone down |
| the address comes from the zone that holds it: 203.0.113.10 | yes | the authoritative zone is the last one asked, which is what authoritative means |
| asking twice with a warm cache saves 3 of 3 queries | yes | the second walk visits the same zones and asks 0 of them, and reaches the same address |
| and the cached walk still ends at the same address | yes | a cache removes questions; it does not shorten the chain of authority |
Three servers, and not one of them held the answer until the last. The root named the top-level domain's servers, those named the domain's own, and only the last had an address. Asked again inside 3600 seconds the whole walk is skipped, which is why the internet does not collapse under the weight of everybody looking things up.
What is real here, and what is not
The zone tree here is a small invented one, and the addresses are reserved
Three names, three top-level domains and one root, so the whole walk fits on a screen. The addresses are all inside 203.0.113.0/24, which RFC 5737 reserves for documentation precisely so that nobody's real host is named on a page like this. The real root has thirteen server names behind a great many machines, and a real walk may involve glue records, several nameservers per zone, and retries.
Nothing here expires on a clock
The time to live is shown and used to decide whether a second walk can skip a step, but the page passes a notional now rather than watching the clock, so a run repeats exactly. A real cache is a race between the record's age and the next question.
There is no security on this page, and the transport is a choice
Everything shown is plain UDP with no authentication of any kind. The lack of authentication is the 1983 design; the UDP-only part is this page's simplification. RFC 882 discusses datagram and reliable virtual-circuit transports both, and RFC 883 specifies Internet access over UDP and TCP on port 53, with the choice depending on the operation. A simple query over a datagram is the path modelled here. DNSSEC, and the various ways of carrying queries inside TLS, are later and are not modelled at all.
A server can also return an error, or an alias
The walk here ends in an answer or a referral, which are the two outcomes worth watching and not the whole protocol. RFC 1034 describes the wider set: a name that does not exist, a server that fails, and CNAME aliases that restart the search under a different name. None of those are on this page, and a resolver that met one would not finish the walk as drawn.
Sources
- P. Mockapetris, Domain Names — Concepts and Facilities, RFC 1034, November 1987, which restates and supersedes the 1983 design in RFC 882.
- P. Mockapetris, Domain Names — Concepts and Facilities, RFC 882, November 1983. The original design, and the reason the resolver on this page is described as one kind of resolver rather than as the resolver: it asks that a resolver have access to at least one name server, not that it know the root.
- P. Mockapetris, Domain Names — Implementation and Specification, RFC 883, November 1983. Where the 1983 design specifies access over both UDP and TCP on port 53, which is why the honesty ledger calls the datagram path a choice made here rather than the standard.
- IANA, Root Files. The root hints an operator of a recursive resolver actually installs, which is the file the first step of this walk stands in for.
- Logical Art, the studio this belongs to.