Lesson 4 of 720 minutesHands-on

Follow a name to an address: run your own DNS lookups

In Lesson 1 you saw that every page load starts with a DNS lookup: turning a name like examineip.com into an address. Your computer does that for you hundreds of times a day without showing you. In this lesson you’ll do it by hand, ask different DNS servers the same question, and learn to read their answers.

In this lesson

  • Run a DNS lookup yourself and read every line of the answer
  • Ask several DNS servers the same question and compare
  • Look up different kinds of record, and see how long an answer is allowed to be remembered

You’ll need: a computer with Windows, macOS or Linux. On a phone? Use our DNS checker for the same lookups, and read along for the rest.

Who answers your DNS questions

Your computer doesn’t work out addresses on its own. It sends the question to a DNS resolver: a server whose job is to find answers. At home that’s usually your router, which passes the question on to a resolver run by your internet provider. You can also choose a public one instead, such as Cloudflare’s 1.1.1.1, Google’s 8.8.8.8 or Quad9’s 9.9.9.9.

If the resolver doesn’t already know the answer, it asks its way down a chain, from the top of the internet’s naming system to the domain’s own servers:

  1. The root servers“Who looks after .com names?”
  2. The .com servers“Who looks after examineip.com?”
  3. The domain’s own name servers“What’s the address of examineip.com?”
  4. Back to youThe resolver hands you the answer and remembers it for a while

That last step is why DNS is fast. The full chain only runs when nobody has asked recently. Most of the time, the resolver already has the answer in its memory, its cache, and replies straight away.

Try it yourself Β· part 1

Your first DNS lookup

The tool for this is called nslookup, and it’s built into Windows and macOS.

πŸͺŸ Windows

Press the Windows key, type cmd and press Enter to open the Command Prompt.

🍎 Mac

Open Terminal: press Cmd + Space, type Terminal and press Enter.

🐧 Linux

Open a terminal. Many distributions don’t include nslookup or dig until you install them. On Ubuntu or Debian:

sudo apt install bind9-dnsutils

Then type this and press Enter:

nslookup examineip.com

You’ll get something like this. Your numbers will be different:

Server: router.home Address: 192.168.1.1Non-authoritative answer: Name: examineip.com Addresses: 2001:db8:24:9441::1 2001:db8:23:d08a::2 198.51.100.87 198.51.100.90

Line by line:

  • Server and Address at the top: the resolver that answered you. If it’s your router’s address from Lesson 2, your router is passing your questions on.
  • Non-authoritative answer means it came from a resolver’s cache, not straight from the domain’s own name servers. That’s normal and nothing to worry about.
  • Addresses: the answer itself. The long ones are IPv6, the short ones IPv4. A site can have several of each, and your browser can use any of them.

Compare these with the Remote Address you found in the developer tools in Lesson 1. That address was one of these.

Try it yourself Β· part 2

Ask different servers the same question

Add a server’s address after the name, and nslookup asks that server instead of your usual one. Try all three:

nslookup examineip.com 1.1.1.1
nslookup examineip.com 8.8.8.8
nslookup examineip.com 9.9.9.9

Now the Server line names the public resolver you chose. Look closely at the addresses. Are they the same every time?

Very often they aren’t. When we ran this, each of the three servers gave us a different pair of addresses, and the same server gave a new pair just seconds later. Nothing is wrong: like many sites, this one is delivered through a content delivery network, which has copies on servers in many places and spreads visitors between them. Each answer points somewhere that can serve you the same pages.

Want to see the answers from around the world at once? Our DNS propagation checker asks many resolvers in different countries the same question.

Try it yourself Β· part 3

Look up a name that doesn’t exist

nslookup no-such-domain-zz9q8.com 1.1.1.1

This time the answer starts with can't find no-such-domain-zz9q8.com: Non-existent domain. That’s the DNS way of saying “this name isn’t registered”. In a browser, the same answer appears as an error like DNS_PROBE_FINISHED_NXDOMAIN or ERR_NAME_NOT_RESOLVED. Now you know what’s behind those messages: the lookup in step 1 of the journey failed, so nothing else could happen.

DNS stores more than addresses

A domain’s DNS holds several kinds of record, each answering a different question. These are the ones you’ll meet most:

RecordWhat it answers
AThe IPv4 address for a name
AAAAThe IPv6 address for a name
CNAME“This name is really another name”: look that one up instead
MXWhich server receives email for the domain
TXTNotes in text, often used to prove who’s allowed to send the domain’s email
NSWhich name servers are in charge of the domain

Try it yourself Β· part 4

Ask for a specific kind of record

Add -type= and the record you want. Where does Google’s email go?

nslookup -type=mx google.com

The answer names a mail server, smtp.google.com. Now ask who’s in charge of a domain’s DNS:

nslookup -type=ns examineip.com

These are the domain’s own name servers, the last stop in the chain at the top of this lesson. Our DNS checker shows all of a domain’s records at once if you’d rather not type commands.

Try it yourself Β· part 5

See how long an answer is remembered

Every DNS answer comes with a TTL, short for “time to live”: the number of seconds a resolver may keep it in its cache before it has to ask again. nslookup hides it, so use one of these:

πŸͺŸ Windows (PowerShell)

Press the Windows key, type powershell and press Enter, then:

Resolve-DnsName examineip.com -Server 1.1.1.1

The TTL column shows the seconds left.

🍎 Mac and 🐧 Linux
dig examineip.com @1.1.1.1

In the ANSWER SECTION, the number after the name is the TTL in seconds.

Run it a few times, a few seconds apart, and watch the TTL go down. When it reaches zero, the resolver throws the answer away and fetches a fresh one. This site uses a TTL of 60 seconds, so answers about it are refreshed every minute; many sites use an hour or a day.

The TTL is why a change to a domain’s DNS doesn’t reach everyone at once: each resolver keeps the old answer until its timer runs out. Your own computer keeps a cache too, which is why flushing the DNS cache fixes some “it works for everyone but me” problems.

Why it matters who answers

Whoever runs your resolver sees every name you look up, which is most of the websites you visit, even when the pages themselves are encrypted. They also decide what answer you get. That’s why DNS shows up again and again in this course:

Key takeaways

  • Your device asks a DNS resolver, usually through your router, which finds the answer or already has it cached.
  • nslookup name asks your usual resolver; nslookup name 1.1.1.1 asks a specific one.
  • Different answers from different servers are normal for sites on a content delivery network.
  • “Non-existent domain” is what’s behind NXDOMAIN and “name not resolved” errors in your browser.
  • A, AAAA, MX, TXT, CNAME and NS records each answer a different question, and every answer has a TTL.

Check yourself

Three questions. Pick one answer each and you’ll see why.

1. You run nslookup examineip.com 1.1.1.1. What is 1.1.1.1 in that command?

2. Two DNS servers give you different addresses for the same big website. What’s the most likely reason?

3. What does a DNS record’s TTL tell you?

Want the background in more depth? Read What Is DNS?, the full explainer this lesson builds on.

Scroll to Top