Skip to main content

Command Palette

Search for a command to run...

How DNS Resolution Works

DNS Resolution

Updated
•5 min read•View as Markdown
How DNS Resolution Works

What is DNS and Why Name Resolution Exists

The Domain Name System (DNS) is often called the “phonebook of the internet.” It translates human-readable domain names like google.com into machine-readable IP addresses like 142.250.183.14.

Computers communicate using IP addresses, not names. However, humans cannot realistically remember numeric IP addresses for every website they visit. Name resolution exists to solve this problem.

Name resolution is the process of converting a domain name into its corresponding IP address. Without DNS, users would have to memorize IP addresses for every website. DNS makes the internet usable, scalable, and flexible. It also allows server IP addresses to change without affecting users, because the domain name remains the same.

In short:

DNS = Human-friendly names
IP Address = Machine-friendly numbers
Name Resolution = The conversion between them


What is the dig Command and When It Is Used

dig stands for Domain Information Groper. It is a command-line tool used to query DNS servers and inspect DNS records.

Developers, system administrators, and DevOps engineers use dig to:

  • Check if a domain resolves correctly

  • Debug DNS configuration issues

  • Inspect specific DNS record types (A, NS, MX, etc.)

  • Understand the DNS resolution process

Example:

dig google.com

This command queries DNS and shows:

  • The answer section (resolved IP)

  • Authority section

  • Additional information

  • Query time

  • The DNS server that responded

dig is primarily used for troubleshooting and learning how DNS works internally.


Understanding dig . NS and Root Name Servers

When you run:

dig . NS

The dot (.) represents the root of the DNS hierarchy.

DNS is structured like a tree:

. (root)
 ├── com
 ├── org
 ├── net
 └── in

Root name servers sit at the top of this hierarchy. They do not know the IP address of google.com, but they know which servers handle the .com domain.

When asked about a domain, root servers respond with a referral to the appropriate Top-Level Domain (TLD) servers.

Root servers are the starting point of the global DNS resolution process.


Understanding dig com NS and TLD Name Servers

When you run:

dig com NS

You are asking: “Which name servers manage the .com domain?”

These are called Top-Level Domain (TLD) name servers.

TLD servers manage domains under their extension (like .com, .org, .net). They do not know the exact IP of google.com, but they know which authoritative name servers are responsible for it.

So the flow becomes:

Root server → Points to TLD server

TLD server → Points to authoritative server


Understanding dig google.com NS and Authoritative Name Servers

When you run:

dig google.com NS

You are asking: “Which name servers are authoritative for google.com?”

Authoritative name servers are responsible for storing the actual DNS records of a domain, such as:

  • A records (IPv4)

  • AAAA records (IPv6)

  • MX records (mail)

  • TXT records (verification)

  • CNAME records (aliases)

These servers contain the final and official DNS information for the domain.

They provide the actual answer to the query.


Understanding dig google.com and the Full DNS Resolution Flow

When you run:

dig google.com

Here is the complete DNS resolution process:

Step 1: Check Local Cache

The system first checks:

  • Browser cache

  • Operating system cache

  • Router cache

If the record is found, resolution ends here.

Step 2: Query Recursive Resolver

If not found locally, the query goes to a recursive resolver (usually provided by your ISP or a public DNS like 8.8.8.8).

Step 3: Ask Root Server

The resolver asks the root server:

“Where is google.com?”

Root replies:

“I do not know, but ask the .com TLD servers.”

Step 4: Ask TLD Server

The resolver asks the .com TLD server:

“Where is google.com?”

TLD replies:

“Ask these authoritative name servers.”

Step 5: Ask Authoritative Server

The resolver asks Google’s authoritative server:

“What is the A record for google.com?”

Authoritative server replies with the IP address.

Step 6: Return the IP to Client

The resolver sends the IP address back to your system.

Your browser then connects to that IP using TCP and loads the website.


Complete DNS Resolution Flow (Summary)

Client

↓

Recursive Resolver

↓

Root Server

↓

TLD Server

↓

Authoritative Server

↓

IP Address Returned


Conclusion

DNS is a hierarchical, distributed system that translates domain names into IP addresses. The dig command allows us to inspect each step of this process. By querying root servers, TLD servers, and authoritative servers, we can understand how the internet locates websites.

Without DNS, the modern internet would not be usable. It is one of the foundational systems that makes global communication possible.