Why Now Daily.

Published

How DNS Works: Resolvers, Caching, DoH and DNSSEC

DNS is a distributed naming system in which a recursive resolver finds and caches records published by authoritative servers; DoH encrypts transport to a resolver, while DNSSEC authenticates signed DNS data.

Timeline

  1. Request: An application asks a configured recursive resolver for a record associated with a domain name.
  2. Resolve: The resolver uses cached data or follows referrals through the DNS hierarchy to an authoritative server.
  3. Connect: The resolver returns the record, and the application separately connects to the resulting service address.

The Domain Name System, or DNS, lets people use names such as example.com instead of remembering numerical Internet Protocol addresses. A browser asks for records associated with the name before it can contact the destination service. DNS is distributed: no single server contains every answer, and a domain name can publish several kinds of record for websites, mail delivery, aliases, service discovery and other purposes. [1][2]

Most devices send the question to a recursive resolver selected by the network, operating system, browser or user. If the answer is not cached, the resolver follows referrals through the hierarchy: a root server points toward the relevant top-level domain, that level points toward the domain's authoritative nameservers, and an authoritative server returns the published record. The recursive resolver performs this work and returns the result to the application. [2][3]

Authoritative and recursive service are different roles. An authoritative nameserver holds the definitive records for zones it serves; a recursive resolver seeks answers on behalf of clients. A registrar records where a domain's authoritative nameservers are delegated, while a DNS hosting provider operates those servers. Neither role normally hosts the website content itself. Changing a web host, registrar, authoritative DNS provider or recursive resolver therefore changes different parts of the path. [1][2]

Caching speeds repeated lookups and reduces work for the hierarchy. Each record has a time to live, or TTL, chosen by the zone publisher. A resolver can reuse the cached answer until that interval expires, after which it should ask an authoritative server again. This explains why a DNS change may appear at different times for different users: their resolvers can hold answers obtained at different moments, up to the applicable TTL and cache policy. [3][4]

DNS over HTTPS, or DoH, maps DNS query-response pairs into HTTPS exchanges. Encryption can prevent a local network observer from reading or altering the request between the client and the chosen DoH resolver. It does not make the domain trustworthy, hide subsequent connections from every observer or eliminate the resolver's visibility. Selecting DoH also selects an operator and privacy policy, so encrypted transport and provider trust are separate decisions. [5]

DNSSEC solves a different problem. Signed DNS data lets a validating resolver verify its origin and detect modification through a chain of trust. It authenticates records from signed zones; it does not encrypt the query, conceal which name was requested or certify that a website is harmless. DoH can carry signed or unsigned data, and conventional DNS transport can carry DNSSEC data, so the two mechanisms can be used together but are not substitutes. [6]

For routine troubleshooting, separate name resolution from the later web connection. Test another known domain, check whether multiple devices or one network are affected, inspect the configured resolver and avoid clearing caches unless stale data is plausible. Domain operators should verify delegations, authoritative records, TTLs and DNSSEC signatures before a migration. Users changing resolver settings should record the original configuration and understand that filters, parental controls and corporate policies may depend on the existing provider. [1][2][3][4][5][6]

Sources

  1. ICANN — The Domain Name System
  2. Cloudflare Learning Center — What Is DNS?
  3. Internet Society — The Internet Domain Name System Explained
  4. ICANN RSSAC — Root Server System FAQ
  5. IETF RFC 8484 — DNS Queries over HTTPS
  6. ICANN — DNSSEC: What Is It and Why Is It Important?

Related stories