What Is DNS? – Simple Explanation

Key Takeaway:
DNS — the Domain Name System — turns names people can remember, like example.com, into the IP addresses computers actually connect to. Every time you open a website, send an email or use an app, your device makes DNS lookups first, usually in a few milliseconds. Whoever answers those lookups can see every site you visit and could send you to the wrong place, so which DNS server you use matters for privacy and security as well as speed.

👉 See the DNS records behind any domain with the free DNS checker.


Why the Internet Needs DNS

Computers find each other using IP addresses — numbers like 192.0.2.10, or longer IPv6 addresses like 2001:db8::10. People are bad at remembering those, and the addresses behind a website can change whenever it moves to a new server or network.

DNS solves both problems. You remember a name; DNS looks up the current address for it. The site can move servers, add more of them, or put them in different countries, and the name keeps working. It’s often described as the internet’s phone book, although it’s closer to a vast, distributed directory that no single organisation holds in full.

It has been around since 1983, when Paul Mockapetris designed it to replace a single shared text file, HOSTS.TXT, that every computer on the early internet had to download to know other machines’ addresses. That file couldn’t keep up as the network grew; DNS spread the job across many servers instead.

🔍 How a DNS Lookup Works, Step by Step

Say you type www.example.com into your browser, and nothing about it is cached anywhere yet:

  1. Your device checks its own cache. Browsers and operating systems remember recent answers. If the address is there, the lookup ends immediately.
  2. It asks a recursive resolver. This is the DNS server your device is set to use — normally your ISP’s, handed out by your router, unless you’ve chosen another one. The resolver does the rest of the work on your behalf.
  3. The resolver asks a root server: “Where do I find .com?” The root server doesn’t know the answer, but replies with the servers responsible for .com.
  4. It asks a .com server: “Where do I find example.com?” That server replies with example.com‘s own name servers — the ones listed at the domain’s registrar.
  5. It asks the authoritative name server: “What is the address of www.example.com?” This server holds the domain’s records and gives the real answer.
  6. The resolver returns the answer and caches it for as long as the record’s TTL allows, so the next person who asks gets it instantly.
  7. Your browser connects to that IP address and the page starts to load.

In practice most steps are skipped, because resolvers already have the root and .com servers cached. A full lookup like the one above still usually takes well under a second.

The four kinds of DNS server

Server What it does Who runs it
Recursive resolverTakes your question and chases the answer downYour ISP by default, or a public service you choose
Root serverPoints to the servers for each top-level domain (.com, .org, .uk…)13 named root servers, run by 12 independent organisations from about 2,000 locations worldwide
TLD serverPoints to each domain’s own name serversThe registry for that ending, such as Verisign for .com
Authoritative serverHolds a domain’s actual recordsWhoever hosts the domain’s DNS — a registrar, host or DNS provider

DNS Record Types

A domain’s authoritative server holds several kinds of record, each answering a different question:

Record What it answers Example
AThe IPv4 address for a nameexample.com → 192.0.2.10
AAAAThe IPv6 address for a nameexample.com → 2001:db8::10
CNAME“This name is an alias for that one”www.example.com → example.com
MXWhich servers receive email for the domain, in priority orderexample.com → 10 mail.example.com
TXTFree text: email authentication (SPF, DKIM, DMARC) and ownership checks"v=spf1 include:_spf.example.net -all"
NSWhich servers are authoritative for the domainexample.com → ns1.example.net
SOAAdministrative details for the zone, including default cache timingsPrimary server, contact, serial number
PTRReverse lookup: the name for an IP address192.0.2.10 → mail.example.com
CAAWhich certificate authorities may issue HTTPS certificates for the domain0 issue "letsencrypt.org"

The addresses above come from ranges reserved for documentation. To see real records for any domain — and compare the answers from two public resolvers side by side — use the DNS checker. To see who a domain is registered to and which name servers it uses, try the WHOIS lookup.

Caching, TTL and “DNS Propagation”

Every DNS record carries a TTL — time to live — in seconds. It tells resolvers and devices how long they may reuse an answer before asking again. A TTL of 3600 means an hour.

Caching is why DNS is fast, and also why changes seem slow. When a site moves to a new address, resolvers that cached the old one keep handing it out until their copy expires. People call this “propagation”, but nothing is actually spreading — old answers are simply timing out, at different moments in different places. Lowering a record’s TTL a day or so before a planned change shortens the wait.

If a site works for others but not for you, a stale local cache is a common cause. How to flush your DNS cache covers every major system.


Which DNS Server Are You Using?

Unless you’ve changed something, your router gives your devices your ISP’s resolver. That’s convenient, but it means your ISP receives a list of every domain you look up — see your ISP’s DNS is watching every site you visit. Some ISPs also use DNS to block sites or redirect mistyped addresses to search pages.

To find out what you’re using on each device and router, follow how to check your DNS settings. If you use a VPN, run the VPN leak test — if your ISP’s DNS servers still appear, your lookups are leaking outside the tunnel. What is a DNS leak? explains why.

Public DNS Resolvers Compared

Several organisations run free resolvers anyone can use. They differ less in speed — from most places they’re all quick, and the nearest well-run one usually wins — than in what they log and whether they filter. The logging column summarises each provider’s own published privacy policy, so read the current version before relying on it.

Provider IPv4 addresses Filtering What its policy says about logs
Cloudflare1.1.1.1, 1.0.0.1None on these addressesIP addresses truncated; logs deleted within 25 hours; practices audited by an outside firm
Google Public DNS8.8.8.8, 8.8.4.4NoneFull IP kept in temporary logs for 24–48 hours; a sample kept longer without the IP; not linked to Google accounts
Quad99.9.9.9, 149.112.112.112Blocks known malicious domainsDoesn’t retain client IP addresses; a Swiss foundation under Swiss data protection law
OpenDNS (Cisco)208.67.222.222, 208.67.220.220Optional content filteringRead Cisco’s privacy policy
AdGuard DNS94.140.14.14, 94.140.15.15Blocks ads and trackersRead AdGuard’s privacy policy

A few things worth knowing before you switch:

  • You’re moving trust, not removing it. The new resolver sees your lookups instead of your ISP. Choose one whose policy you’re comfortable with.
  • Speed differences are small. A resolver only affects the moment a connection starts, not download speed. If your internet is slow, DNS is rarely the main cause — see how to fix slow internet.
  • Filtering can block things you want. If a site stops loading after switching to a filtering resolver, that’s the first thing to check.
  • Set it on the router to cover every device at once, or per device if you only want it on one.

🔒 DNS and Security

Classic DNS was designed in a friendlier era. Lookups travel unencrypted, usually over UDP port 53, and answers aren’t signed. That opens the door to a few attacks:

  • Cache poisoning (spoofing) — tricking a resolver into storing a fake answer, so everyone using it is sent to the wrong server.
  • DNS hijacking — changing which resolver you use, most often through malware or a router with a weak admin password. Every lookup then goes to the attacker. Securing your home network covers the router side.
  • Snooping — anyone on the network path, including your ISP or a public Wi-Fi operator, can read unencrypted lookups.

Two separate technologies address different parts of this, and they’re often confused:

Technology What it does What it doesn’t do
DNSSECSigns records so a validating resolver can tell a forged answer from a real oneEncrypt anything — lookups stay readable. Only works for domains that have signed their records.
DNS over HTTPS / TLS (DoH, DoT)Encrypts lookups between your device and the resolver (DoH on port 443, DoT on 853), so the network can’t read or alter themHide your lookups from the resolver itself, or hide which sites you connect to — the IP addresses are still visible

The DNS checker shows whether a resolver validated a domain’s DNSSEC signatures. What is DNS over HTTPS? explains how to turn encrypted DNS on in your browser or system.

How to Check DNS Is Working

Open a terminal and ask for a domain’s address:

Windows (Command Prompt):   nslookup example.com
Windows (PowerShell):       Resolve-DnsName example.com
macOS and Linux:            dig example.com
Ask a specific resolver:    nslookup example.com 9.9.9.9

If you get an address back, DNS is working. If the lookup times out but asking 9.9.9.9 directly works, the problem is your usual resolver. If websites load by IP address but not by name, DNS is the culprit. These guides cover the common errors:


Frequently Asked Questions

What does DNS stand for?

Domain Name System. It’s the system that translates domain names into the IP addresses computers use to connect.

What happens if DNS stops working?

Websites and apps stop loading by name, and browsers show errors such as “DNS_PROBE_FINISHED_NXDOMAIN” or “server IP address could not be found”. Your connection itself is usually fine — anything reached by IP address still works.

Is it safe to use 8.8.8.8 or 1.1.1.1?

Yes. Both are long-established public resolvers run by large companies with published privacy policies. The trade-off is that the provider sees your lookups instead of your ISP.

Will changing DNS make my internet faster?

Occasionally a little, when your ISP’s resolver is slow or unreliable. It only affects how quickly connections start — not download or upload speed.

Does a VPN change my DNS?

A properly configured VPN sends your lookups through the tunnel to its own resolvers. If it doesn’t, your ISP still sees every domain you visit. Check with the VPN leak test.

Can DNS block websites?

Yes. Filtering resolvers refuse to answer for domains on their block lists — malware, ads or adult content, depending on the service. ISPs and governments sometimes use the same technique to block sites.

Why does a website work on my phone but not my computer?

The two devices are probably using different resolvers or have different cached answers. Flush the computer’s DNS cache, or compare the DNS settings on both.

What is reverse DNS?

The opposite lookup: finding the name attached to an IP address, using a PTR record. Mail servers rely on it to judge whether an incoming server is legitimate.


Related Reading

Scroll to Top