Key Takeaway:
DNS — the Domain Name System — turns names people can remember, like example.com, into the IP addresses computers actually connect to. Every time you open a website, send an email or use an app, your device makes DNS lookups first, usually in a few milliseconds. Whoever answers those lookups can see every site you visit and could send you to the wrong place, so which DNS server you use matters for privacy and security as well as speed.
👉 See the DNS records behind any domain with the free DNS checker.
Why the Internet Needs DNS
Computers find each other using IP addresses — numbers like 192.0.2.10, or longer IPv6 addresses like 2001:db8::10. People are bad at remembering those, and the addresses behind a website can change whenever it moves to a new server or network.
DNS solves both problems. You remember a name; DNS looks up the current address for it. The site can move servers, add more of them, or put them in different countries, and the name keeps working. It’s often described as the internet’s phone book, although it’s closer to a vast, distributed directory that no single organisation holds in full.
It has been around since 1983, when Paul Mockapetris designed it to replace a single shared text file, HOSTS.TXT, that every computer on the early internet had to download to know other machines’ addresses. That file couldn’t keep up as the network grew; DNS spread the job across many servers instead.
🔍 How a DNS Lookup Works, Step by Step
Say you type www.example.com into your browser, and nothing about it is cached anywhere yet:
- Your device checks its own cache. Browsers and operating systems remember recent answers. If the address is there, the lookup ends immediately.
- It asks a recursive resolver. This is the DNS server your device is set to use — normally your ISP’s, handed out by your router, unless you’ve chosen another one. The resolver does the rest of the work on your behalf.
- The resolver asks a root server: “Where do I find .com?” The root server doesn’t know the answer, but replies with the servers responsible for .com.
- It asks a .com server: “Where do I find example.com?” That server replies with example.com‘s own name servers — the ones listed at the domain’s registrar.
- It asks the authoritative name server: “What is the address of www.example.com?” This server holds the domain’s records and gives the real answer.
- The resolver returns the answer and caches it for as long as the record’s TTL allows, so the next person who asks gets it instantly.
- Your browser connects to that IP address and the page starts to load.
In practice most steps are skipped, because resolvers already have the root and .com servers cached. A full lookup like the one above still usually takes well under a second.
The four kinds of DNS server
| Server | What it does | Who runs it |
|---|---|---|
| Recursive resolver | Takes your question and chases the answer down | Your ISP by default, or a public service you choose |
| Root server | Points to the servers for each top-level domain (.com, .org, .uk…) | 13 named root servers, run by 12 independent organisations from about 2,000 locations worldwide |
| TLD server | Points to each domain’s own name servers | The registry for that ending, such as Verisign for .com |
| Authoritative server | Holds a domain’s actual records | Whoever hosts the domain’s DNS — a registrar, host or DNS provider |
DNS Record Types
A domain’s authoritative server holds several kinds of record, each answering a different question:
| Record | What it answers | Example |
|---|---|---|
| A | The IPv4 address for a name | example.com → 192.0.2.10 |
| AAAA | The IPv6 address for a name | example.com → 2001:db8::10 |
| CNAME | “This name is an alias for that one” | www.example.com → example.com |
| MX | Which servers receive email for the domain, in priority order | example.com → 10 mail.example.com |
| TXT | Free text: email authentication (SPF, DKIM, DMARC) and ownership checks | "v=spf1 include:_spf.example.net -all" |
| NS | Which servers are authoritative for the domain | example.com → ns1.example.net |
| SOA | Administrative details for the zone, including default cache timings | Primary server, contact, serial number |
| PTR | Reverse lookup: the name for an IP address | 192.0.2.10 → mail.example.com |
| CAA | Which certificate authorities may issue HTTPS certificates for the domain | 0 issue "letsencrypt.org" |
The addresses above come from ranges reserved for documentation. To see real records for any domain — and compare the answers from two public resolvers side by side — use the DNS checker. To see who a domain is registered to and which name servers it uses, try the WHOIS lookup.
Caching, TTL and “DNS Propagation”
Every DNS record carries a TTL — time to live — in seconds. It tells resolvers and devices how long they may reuse an answer before asking again. A TTL of 3600 means an hour.
Caching is why DNS is fast, and also why changes seem slow. When a site moves to a new address, resolvers that cached the old one keep handing it out until their copy expires. People call this “propagation”, but nothing is actually spreading — old answers are simply timing out, at different moments in different places. Lowering a record’s TTL a day or so before a planned change shortens the wait.
If a site works for others but not for you, a stale local cache is a common cause. How to flush your DNS cache covers every major system.
Which DNS Server Are You Using?
Unless you’ve changed something, your router gives your devices your ISP’s resolver. That’s convenient, but it means your ISP receives a list of every domain you look up — see your ISP’s DNS is watching every site you visit. Some ISPs also use DNS to block sites or redirect mistyped addresses to search pages.
To find out what you’re using on each device and router, follow how to check your DNS settings. If you use a VPN, run the VPN leak test — if your ISP’s DNS servers still appear, your lookups are leaking outside the tunnel. What is a DNS leak? explains why.
Public DNS Resolvers Compared
Several organisations run free resolvers anyone can use. They differ less in speed — from most places they’re all quick, and the nearest well-run one usually wins — than in what they log and whether they filter. The logging column summarises each provider’s own published privacy policy, so read the current version before relying on it.
| Provider | IPv4 addresses | Filtering | What its policy says about logs |
|---|---|---|---|
| Cloudflare | 1.1.1.1, 1.0.0.1 | None on these addresses | IP addresses truncated; logs deleted within 25 hours; practices audited by an outside firm |
| Google Public DNS | 8.8.8.8, 8.8.4.4 | None | Full IP kept in temporary logs for 24–48 hours; a sample kept longer without the IP; not linked to Google accounts |
| Quad9 | 9.9.9.9, 149.112.112.112 | Blocks known malicious domains | Doesn’t retain client IP addresses; a Swiss foundation under Swiss data protection law |
| OpenDNS (Cisco) | 208.67.222.222, 208.67.220.220 | Optional content filtering | Read Cisco’s privacy policy |
| AdGuard DNS | 94.140.14.14, 94.140.15.15 | Blocks ads and trackers | Read AdGuard’s privacy policy |
A few things worth knowing before you switch:
- You’re moving trust, not removing it. The new resolver sees your lookups instead of your ISP. Choose one whose policy you’re comfortable with.
- Speed differences are small. A resolver only affects the moment a connection starts, not download speed. If your internet is slow, DNS is rarely the main cause — see how to fix slow internet.
- Filtering can block things you want. If a site stops loading after switching to a filtering resolver, that’s the first thing to check.
- Set it on the router to cover every device at once, or per device if you only want it on one.
🔒 DNS and Security
Classic DNS was designed in a friendlier era. Lookups travel unencrypted, usually over UDP port 53, and answers aren’t signed. That opens the door to a few attacks:
- Cache poisoning (spoofing) — tricking a resolver into storing a fake answer, so everyone using it is sent to the wrong server.
- DNS hijacking — changing which resolver you use, most often through malware or a router with a weak admin password. Every lookup then goes to the attacker. Securing your home network covers the router side.
- Snooping — anyone on the network path, including your ISP or a public Wi-Fi operator, can read unencrypted lookups.
Two separate technologies address different parts of this, and they’re often confused:
| Technology | What it does | What it doesn’t do |
|---|---|---|
| DNSSEC | Signs records so a validating resolver can tell a forged answer from a real one | Encrypt anything — lookups stay readable. Only works for domains that have signed their records. |
| DNS over HTTPS / TLS (DoH, DoT) | Encrypts lookups between your device and the resolver (DoH on port 443, DoT on 853), so the network can’t read or alter them | Hide your lookups from the resolver itself, or hide which sites you connect to — the IP addresses are still visible |
The DNS checker shows whether a resolver validated a domain’s DNSSEC signatures. What is DNS over HTTPS? explains how to turn encrypted DNS on in your browser or system.
How to Check DNS Is Working
Open a terminal and ask for a domain’s address:
Windows (Command Prompt): nslookup example.com Windows (PowerShell): Resolve-DnsName example.com macOS and Linux: dig example.com Ask a specific resolver: nslookup example.com 9.9.9.9
If you get an address back, DNS is working. If the lookup times out but asking 9.9.9.9 directly works, the problem is your usual resolver. If websites load by IP address but not by name, DNS is the culprit. These guides cover the common errors:
- DNS_PROBE_FINISHED_NXDOMAIN — the name couldn’t be found.
- “DNS server not responding” — the resolver isn’t answering.
- ERR_NAME_NOT_RESOLVED — Chrome’s version of a failed lookup.
Frequently Asked Questions
What does DNS stand for?
Domain Name System. It’s the system that translates domain names into the IP addresses computers use to connect.
What happens if DNS stops working?
Websites and apps stop loading by name, and browsers show errors such as “DNS_PROBE_FINISHED_NXDOMAIN” or “server IP address could not be found”. Your connection itself is usually fine — anything reached by IP address still works.
Is it safe to use 8.8.8.8 or 1.1.1.1?
Yes. Both are long-established public resolvers run by large companies with published privacy policies. The trade-off is that the provider sees your lookups instead of your ISP.
Will changing DNS make my internet faster?
Occasionally a little, when your ISP’s resolver is slow or unreliable. It only affects how quickly connections start — not download or upload speed.
Does a VPN change my DNS?
A properly configured VPN sends your lookups through the tunnel to its own resolvers. If it doesn’t, your ISP still sees every domain you visit. Check with the VPN leak test.
Can DNS block websites?
Yes. Filtering resolvers refuse to answer for domains on their block lists — malware, ads or adult content, depending on the service. ISPs and governments sometimes use the same technique to block sites.
Why does a website work on my phone but not my computer?
The two devices are probably using different resolvers or have different cached answers. Flush the computer’s DNS cache, or compare the DNS settings on both.
What is reverse DNS?
The opposite lookup: finding the name attached to an IP address, using a PTR record. Mail servers rely on it to judge whether an incoming server is legitimate.