Domain Name System definition
DNS (Domain Name System) is the internet's directory service that translates human-readable domain names such as example.com into the IP addresses computers use to connect. When you open a website or call an API, a DNS resolver looks up the name through a hierarchy of servers and caches the answer for a set time to speed up future lookups.
How does DNS work?
When you type a domain into a browser, your device asks a recursive resolver, usually run by your internet provider or a public service such as Cloudflare's 1.1.1.1 or Google's 8.8.8.8. If the answer is not cached, the resolver asks a root server which servers handle the top-level domain, such as .com, then asks those servers which nameservers are authoritative for the domain, and finally asks the authoritative nameserver for the record itself.
The answer comes back with a time to live (TTL), the number of seconds resolvers may cache it. Most lookups are answered from caches in milliseconds, which is why DNS feels instant even though it is a global, distributed system with no single central server. Every web request, API call and email delivery starts with a lookup like this.
Common DNS record types
A domain's DNS zone is a set of records, each mapping a name to a value. These are the records teams touch most often when launching a website, moving to new hosting, verifying a domain with a SaaS tool or setting up company email:
- A and AAAA: map a name to an IPv4 or IPv6 address
- CNAME: make one name an alias of another, such as www pointing to a hosting platform
- MX: name the mail servers that accept email for the domain
- TXT: hold text used for domain verification and email security records such as SPF, DKIM and DMARC
- NS: list the authoritative nameservers for the domain or a subdomain
- CAA: restrict which certificate authorities may issue TLS certificates for the domain
TTL, propagation and planned DNS changes
When you change a record, resolvers that cached the old answer keep using it until the TTL expires. This delay is what people call DNS propagation. Before a planned migration, lower the TTL to a few minutes a day or two ahead, make the change, confirm traffic has moved, then raise the TTL again. Changing nameservers at the registrar can take longer, because the parent zone's records carry their own, often long, TTLs.
DNS is also a traffic management tool. Managed services such as Amazon Route 53, Cloudflare DNS and Azure DNS support health checks, failover to a standby region and latency-based or geographic routing, which makes DNS a building block of high availability designs and of most CDN setups.
DNS security risks and protections
Because so much depends on DNS, attackers target it. Hijacked registrar accounts let attackers redirect a whole domain, so protect them with MFA and registry lock. Dangling CNAME records pointing at deleted cloud resources enable subdomain takeover. Cache poisoning tries to insert false answers into resolvers, which DNSSEC counters by signing records cryptographically. DNS over HTTPS and DNS over TLS encrypt lookups between devices and resolvers for privacy.
Nexzem audits DNS as part of website launches and cloud migrations: removing stale records that could be taken over, adding SPF, DKIM and DMARC so company email is not spoofed, and setting TTLs that make the next change painless instead of a long, nervous wait.