What Is DNS? How the Domain Name System Works
A plain explanation of DNS: resolvers, root and TLD servers, authoritative nameservers, records, TTL and caching, and exactly what happens when someone types your domain.

Table of Contents
DNS (the Domain Name System) is the internet's directory: it translates names people can remember, like example.com, into the IP addresses computers use to connect, like 203.0.113.10. It also tells mail servers where to deliver email for a domain and stores other information such as verification records.
Every website visit and every email to your domain starts with DNS, so understanding it makes most domain and hosting problems much easier to solve.
What happens in a DNS lookup
When someone types www.example.com into a browser:
- The device checks its own cache. If it looked up the name recently and the answer has not expired, it uses that.
- It asks a recursive resolver, usually run by the internet provider, or a public resolver the device is set to use.
- The resolver asks a root server where to find
.comdomains. The root server points to the.comTLD servers. - The resolver asks a
.comTLD server which nameservers are responsible forexample.com. The TLD server answers with the domain's nameservers, as registered at the registrar. - The resolver asks one of those authoritative nameservers for the record it needs (for example the A record of
www.example.com) and gets the IP address. - The resolver returns the answer to the device and caches it for the record's TTL.
- The browser connects to that IP address.
All of this usually takes a few milliseconds to a few hundred milliseconds, and caching makes repeat lookups almost instant.
The key pieces
| Piece | Role |
|---|---|
| Recursive resolver | Does the lookup work on behalf of the user and caches answers |
| Root servers | Point to the servers for each top-level domain |
| TLD servers | Point to each domain's nameservers |
| Authoritative nameservers | Hold the domain's actual DNS records |
| DNS zone | The set of records for a domain, managed at the DNS host |
| TTL (time to live) | How long resolvers may cache an answer, in seconds |
Nameservers vs records
Two settings are often confused:
- Nameservers are set at your registrar and say who answers for your domain.
- DNS records are set at your DNS host (whichever service those nameservers belong to) and say what the answers are.
If you change nameservers, the records at the old DNS host stop being used. This is explained further in nameservers vs DNS records.
Common record types
- A and AAAA: the IPv4 and IPv6 address of a name.
- CNAME: an alias pointing one name to another.
- MX: the mail servers for the domain.
- TXT: text data, used for SPF, DKIM, DMARC and verification.
- NS: the nameservers.
- CAA: which certificate authorities may issue SSL certificates.
Each type is explained with examples in DNS record types explained.
TTL and caching
Every record has a TTL. A TTL of 3600 means resolvers can keep the answer for an hour. Long TTLs reduce lookups; short TTLs let changes take effect sooner. When you plan to change an important record, lower its TTL in advance. See DNS propagation explained.
DNS and security
- DNSSEC adds cryptographic signatures to DNS answers, so resolvers can detect forged responses. It must be supported by the registry, the registrar and the DNS host.
- Registrar lock and account 2FA protect against someone changing your nameservers. See preventing domain hijacking.
- Encrypted DNS (DNS over HTTPS or TLS) protects lookups between users and their resolver from eavesdropping.
Seeing DNS work for yourself
You can watch DNS resolution with a few commands:
dig example.com A +short # the website's IPv4 address
dig example.com MX +short # the mail servers
dig NS example.com +short # the authoritative nameservers
dig example.com +trace # follow the lookup from the root servers down
On Windows, nslookup does a similar job: nslookup -type=MX example.com. The +trace option is especially instructive: it shows the root servers referring to the .com servers, which refer to the domain's nameservers, which finally answer.
Where DNS fits with your other services
| Service | DNS records involved |
|---|---|
| Website | A / AAAA for the domain, CNAME or A for www |
| MX, plus SPF, DKIM and DMARC (TXT) | |
| SSL certificates | Validation records (sometimes), CAA to restrict issuers |
| Third-party services | CNAME or TXT records for verification and connection |
| Subdomains | A or CNAME for each one |
Most problems when moving hosting or email come from a record in this table being forgotten.
The DNS learning path
- Nameservers vs DNS records
- DNS record types explained
- MX records explained
- SPF, DKIM and DMARC explained
- DNS propagation explained
- How to edit DNS records in cPanel Zone Editor
- How to set up Cloudflare DNS
Common DNS problems
- Website not loading after a change: caching; wait for the TTL or check from another network.
- Email stops after moving hosts: MX or SPF records were not recreated at the new DNS host.
- Changes have no effect: you edited records at a DNS host that is not the one your nameservers point to.
- Domain resolves nowhere: it expired, is on hold, or the nameservers are wrong. See what is WHOIS to check status.
Frequently Asked Questions
Who provides DNS for my domain?
Whoever runs the nameservers set at your registrar: often your registrar, your hosting provider, or a DNS service such as Cloudflare.
Does DNS affect website speed?
Slightly, on the first visit. A fast, reliable DNS provider helps, but DNS is rarely the main cause of a slow site.
Is DNS the same as hosting?
No. DNS tells visitors where your website is; hosting is where it actually runs.
Related reading
For how domains themselves work, see domain names explained. To connect a domain to hosting, follow how to point a domain to hosting. Register or manage domains through the ServerNeed domain search.
Sources
Last updated 7 October 2026



