DNS
Domain Name System
The global directory that turns names people can read, such as example.com, into the numeric addresses computers use. It is organized like a tree. The root zone The top of the DNS, listing every TLD and its name servers. Full definition of root zone is at the top, then top-level domains, then the names below them. Without it, domain name A readable internet name made of labels separated by dots. Full definition of domain name would not work.
- category
- DNS and technical foundations
The DNS (Domain Name System) is the internet’s directory. Devices are reached by numeric IP Internet Protocol The internet's basic rules for sending data, using numeric addresses for every connected device. Full definition of IP (IPv4 or IPv6), handed out separately from domain names, but people use names such as example.com. The DNS links the two, so that a name typed in a browser or used in an email address reaches the right computer. No single organisation holds the whole directory: it is spread across many servers run by many operators, which keep answers locally for a while to speed things up.
What the DNS is and why the internet needs it
The DNS is shaped like a tree. The root zone is at the top. Below it are the top-level domains (TLD top-level domain The last part of a domain name, after the final dot. Full definition of TLD), such as .com or .es, and below those are the names people register. A name can hold several kinds of records: addresses (A record A DNS record that points a domain name to an IPv4 address. Full definition of A record for IPv4, AAAA record A DNS record that points a domain name to an IPv6 address. Full definition of AAAA record for IPv6), but also the names of the servers responsible for it (NS record Name Server record A DNS record that lists the name servers responsible for a domain. Full definition of NS record) and security data for DNSSEC Domain Name System Security Extensions Digital signatures that prove DNS answers are genuine and unchanged. Full definition of DNSSEC.
What happens when you type a domain name: a lookup step by step
Suppose an app needs the address of www.example.com.
- The app asks the stub resolver The simple DNS client on a device that passes lookups to a recursive resolver. Full definition of stub resolver, a small piece of DNS software on the device. It passes the question to a recursive resolver The DNS server that looks up domain names on behalf of users. Full definition of resolver, usually run by the internet service provider or by a public DNS resolver A DNS resolver open for anyone on the internet to use. Full definition of public DNS resolver service.
- The recursive resolver first checks its cache. If it already holds the answer and the answer’s TTL Time to Live How long resolvers may keep a saved copy of a DNS record. Full definition of TTL (time to live) has not run out, it replies at once.
- If not, it starts at the top. It knows the addresses of the root server A server that answers for the DNS root zone and points to TLD servers. Full definition of root server from a built-in list, the root hints The list of root server names and addresses that a resolver starts from. Full definition of root hints.
- A root server does not know the address of
www.example.com. It replies with a referral: where to find the servers for .com. - A .com server does not know the final answer either. It replies with a referral to the name server A server that holds a domain's DNS records and answers lookups. Full definition of name server that the holder of example.com chose.
- One of those name servers is authoritative for example.com. It returns the address in an A or AAAA record. The resolver keeps the answer for as long as its TTL allows and passes it to the device.
Resolvers and authoritative servers: who asks and who answers
Resolvers ask questions on behalf of users. authoritative server A DNS server that gives the official answers for a domain or zone. Full definition of authoritative server answer them from the data of the zones they hold, without asking any other server. They are a domain’s name servers, listed in its NS records.
Some recursive resolvers are public DNS resolvers: services meant to be used by anyone on the internet, instead of the one supplied by the internet provider. The technical term “open resolver” usually means something else: a resolver that answers anyone by mistake because it is badly configured.
Because every lookup passes through a resolver, it is also a place where names can be filtered. The DNS standards include error codes for a name blocked by the operator’s own policy, blocked at someone else’s request, or filtered at the user’s request.
Delegation: how the work is split from the root to your domain
The DNS tree is cut into zones. A cut is made where an organisation wants to control part of the tree, change its data on its own and delegate parts of it further down. A parent zone delegates a child zone by publishing NS records that point to the child’s name servers.
For a domain such as example.com, the chain looks like this:
- IANA Internet Assigned Numbers Authority The functions that coordinate the root zone, IP addresses and protocol numbers. Full definition of IANA manages the root zone and records which servers are responsible for each TLD. PTI Public Technical Identifiers The ICANN affiliate that performs the IANA functions, including root zone changes. Full definition of PTI, an affiliate of ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN, performs the IANA functions, and IANA charges nothing for these services.
- Verisign The company that operates the .com and .net registries. Full definition of Verisign, as Root Zone Maintainer The organization that produces and distributes the root zone file, currently Verisign. Full definition of Root Zone Maintainer under an agreement with ICANN, compiles the root zone file as IANA directs, signs it with DNSSEC and sends it to the root server operator One of the twelve organizations that run the DNS root servers. Full definition of root server operator.
- The root servers answer with referrals to the name servers of each TLD.
- The TLD registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry publishes in its own zone the NS records of each registered name, plus glue record An address record held at the registry for a name server inside the domain it serves. Full definition of glue record and DS record Delegation Signer A record in the parent zone that links a domain's DNSSEC key to the chain of trust. Full definition of DS record where needed.
- The name servers chosen by the domain’s holder answer for the domain itself.
This delegation inside the DNS is different from the delegation of a TLD, which means adding a new top-level domain to the root zone.
Common errors such as NXDOMAIN and SERVFAIL and what they mean
Every DNS answer carries a response code. Two error codes come up often.
NXDOMAIN
NXDOMAIN Non-Existent Domain The DNS answer meaning the requested name does not exist. Full definition of NXDOMAIN (code 3, “name error”) means that the name does not exist, and that no name below it exists either. Typical reasons are a typing mistake, a domain that is not registered, or a domain whose delegation was removed from its TLD zone.
SERVFAIL
SERVFAIL Server Failure The DNS answer meaning the lookup failed, often due to broken name servers or DNSSEC. Full definition of SERVFAIL (code 2, “server failure”) means that the lookup could not be completed. It does not say the name is missing, only that no trustworthy answer was obtained. Common causes are:
- name servers that are listed for a zone but not set up to serve it;
- name servers that do not reply, or network failures on the way;
- RRSIG Resource Record Signature The DNS record that carries a DNSSEC signature for a set of records. Full definition of RRSIG that fail validation, in which case a validating resolver must return SERVFAIL.
A resolver may keep a SERVFAIL answer for five minutes at most. Extended DNS Errors let a server add the reason, such as “DNSSEC Bogus”.
A worked example
Suppose the holder of example.com moves the domain to new name servers but has not yet set them up to serve the zone. Resolvers that follow the new delegation may return SERVFAIL until the new servers are configured.
Who runs the DNS and who pays for it
No single organisation runs the DNS. Each layer has its own operators and its own way of paying.
- Root servers. As of October 2026, 13 named root server identities are run by 12 independent organisations, among them universities, companies and ICANN itself, from more than 2,000 instances around the world. The operators are not paid for this service and fund it themselves.
- TLDs. Each gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD registry must run its TLD’s DNS to service levels set in its contract with ICANN. As of October 2026, under the base registry agreement approved on 12 March 2026, the DNS service must be available 100% of the time, which requires at least two of the TLD’s delegated name servers to answer correctly. A total of 4 hours of DNS downtime in a week is a threshold for an emergency transition of the registry.
- Domains. The holder chooses the authoritative name servers of the domain, either paying a provider for them or using servers included free with another service. Since 1987 the rules have asked for more than one: RFC Request for Comments A numbered document in the series recording the internet's technical standards and practices. Full definition of RFC 1034 expects anyone taking over a zone to show redundant name server support.
- Resolvers. Internet service providers and public DNS services run the resolvers that users rely on.
Sources
- RFC 9499: DNS Terminology, opens another website in a new tab
- RFC 1034: Domain Names - Concepts and Facilities, opens another website in a new tab
- RFC 8914: Extended DNS Errors, opens another website in a new tab
- Root Name Servers (IANA), opens another website in a new tab
- Root Zone Management (IANA), opens another website in a new tab
- Base Registry Agreement (ICANN), approved 12 March 2026, opens another website in a new tab