DNS

No machine anywhere holds a list of every name on the internet. A full recursive resolver with nothing cached begins from its root hints, and and on this walk every server it asks either answers or names the servers to ask instead. That referral is not a failure to answer. It is the answer, and following three or four of them is how a name gets found the first time anybody asks for it. Your laptop almost certainly does none of this itself: it runs a stub resolver that hands the question to a recursive resolver and waits.

New to networks? Start here

A message that takes time and may not arrive

A message takes time to travel from one computer to another. Sending it does not establish that it arrived, and receiving one message does not establish that an earlier one arrived first.

Messages may be delayed, lost, duplicated or reordered. A protocol defines how the participants respond to those possibilities. Some machines here model only one of them; the page says which assumptions its result needs.

The machine for this idea on its own is Packet Switching, if you would rather press it than read about it.

A walk from the root, one referral at a time, and what a cache is worth

1 A resolver that knows one thing: where the root is

The resolver is told the root servers when it is installed and knows nothing else. Pick a name and watch it start from there.

2 The root, which knows the top-level domain

The root does not know the address and never did. What it knows is which servers are authoritative for the top-level domain, and it says so.

Each server consulted, whether the answer came from cache, and whether it referred or answered
zoneaskedsaidkind
the roota.root-servers.neta.cctld.usask them instead
usa.cctld.usns1.logicalart.usask them instead
logicalart.usns1.logicalart.us203.0.113.10the answer

3 The top-level domain, which knows the authoritative server

Each referral is one step further down the tree, and the tree is the name read backwards. The last server in the chain is the only one that holds the address.

the name
logicalart.us
servers asked
3
the address
203.0.113.10

4 The answer, and how long anyone is allowed to keep it

The answer arrives with a time to live, which is a permission rather than a promise: it says how long anybody may keep this before asking again. Ask the same name twice and the second walk is shorter, because the referrals were kept too.

time to live
3600 seconds (60 minutes)
servers asked the second time
0
queries saved
3

These ran in this browser when the page loaded. Each claim, whether it held, and the number behind it.

Each claim, whether it held, and the values behind it
claimheldmeasured
a cold recursive resolver starts at the root, which is the one address its hints file gives ityesthe root -> us -> logicalart.us
exactly one of the 3 steps is an answer and the other 2 are referralsyesa referral is the mechanism working, not a server failing to answer
every referral names the next server, so the walk never stallsyes2 referrals, each naming a server one zone down
the address comes from the zone that holds it: 203.0.113.10yesthe authoritative zone is the last one asked, which is what authoritative means
asking twice with a warm cache saves 3 of 3 queriesyesthe second walk visits the same zones and asks 0 of them, and reaches the same address
and the cached walk still ends at the same addressyesa cache removes questions; it does not shorten the chain of authority

Three servers, and not one of them held the answer until the last. The root named the top-level domain's servers, those named the domain's own, and only the last had an address. Asked again inside 3600 seconds the whole walk is skipped, which is why the internet does not collapse under the weight of everybody looking things up.

What is real here, and what is not

The zone tree here is a small invented one, and the addresses are reserved

Three names, three top-level domains and one root, so the whole walk fits on a screen. The addresses are all inside 203.0.113.0/24, which RFC 5737 reserves for documentation precisely so that nobody's real host is named on a page like this. The real root has thirteen server names behind a great many machines, and a real walk may involve glue records, several nameservers per zone, and retries.

Nothing here expires on a clock

The time to live is shown and used to decide whether a second walk can skip a step, but the page passes a notional now rather than watching the clock, so a run repeats exactly. A real cache is a race between the record's age and the next question.

There is no security on this page, and the transport is a choice

Everything shown is plain UDP with no authentication of any kind. The lack of authentication is the 1983 design; the UDP-only part is this page's simplification. RFC 882 discusses datagram and reliable virtual-circuit transports both, and RFC 883 specifies Internet access over UDP and TCP on port 53, with the choice depending on the operation. A simple query over a datagram is the path modelled here. DNSSEC, and the various ways of carrying queries inside TLS, are later and are not modelled at all.

A server can also return an error, or an alias

The walk here ends in an answer or a referral, which are the two outcomes worth watching and not the whole protocol. RFC 1034 describes the wider set: a name that does not exist, a server that fails, and CNAME aliases that restart the search under a different name. None of those are on this page, and a resolver that met one would not finish the walk as drawn.

Sources