The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

What Is DNS? How the Domain Name System Works

DNS, or the Domain Name System, translates human-readable domain names into IP addresses that computers use to find services on a network. It lets people reach websites and other resources without memorizing numerical addresses.

Why DNS matters

Most people navigate the internet using names such as example.com, not IP addresses. DNS makes that possible by providing a distributed system for matching domain names with the addresses computers use to communicate.

Without DNS, users and applications would need another way to determine where internet resources are located. DNS also separates a service's name from the infrastructure behind it, so an organization can change an IP address without requiring users to learn a new domain name.

DNS supports everyday network activity in several ways:

  • Makes resources easier to find: People can use recognizable domain names instead of numerical IP addresses.
  • Supports changing infrastructure: DNS records can be updated when servers or services move.
  • Speeds up repeated requests: DNS caching allows previously resolved information to be reused for a set period.
  • Provides useful security context: DNS activity can help security teams understand which domains systems are attempting to reach.

Because DNS is a core part of network communication, understanding it is also useful when learning about network security.

How DNS works

A DNS lookup, also called DNS resolution, begins when a device needs to find the IP address associated with a domain. Several DNS components may work together to answer the request. A typical lookup follows this sequence:

  1. A user requests a domain. A browser or application needs the IP address associated with a domain name.
  2. The device checks for a cached answer. If a valid result is already stored locally, another lookup may not be necessary.
  3. A recursive resolver receives the request. If it doesn’t already have the answer cached, it queries other DNS servers.
  4. The resolver follows the DNS hierarchy. A root nameserver directs it toward the appropriate top-level domain (TLD) nameserver, such as the server responsible for .com.
  5. The authoritative nameserver provides the answer. It holds the DNS information for the requested domain and returns the appropriate record.
  6. The IP address returns to the device. The browser or application can then use that address to connect to the destination.

What is DNS caching?

DNS caching temporarily stores information from previous lookups. A cached answer can reduce the number of queries required to resolve a domain, making subsequent requests more efficient.

A DNS record's time to live (TTL) helps determine how long that information can remain cached. Once the TTL expires, the resolver may need to request updated information.

Key components of DNS

DNS is a distributed system rather than a single server or directory. Different components have specific roles in locating and returning DNS information.

  • Recursive DNS resolver: Accepts a DNS request and works to find the requested information. Internet service providers, organizations, and third-party DNS services may operate resolvers.
  • Root nameserver: Points the resolver toward the nameservers responsible for the appropriate top-level domain.
  • TLD nameserver: Provides information about the authoritative nameserver associated with a domain under a TLD such as .com, .org, or .net.
  • Authoritative nameserver: Stores DNS records for a domain and provides authoritative answers to queries about it.
  • DNS records: Stores information associated with a domain. For example, A records map names to IPv4 addresses, AAAA records map names to IPv6 addresses, and MX records identify mail servers.
  • DNS cache: Stores recently resolved records so the same lookup doesn’t always have to repeat the full resolution process.

The term “DNS server” can refer to different systems within this process. A recursive resolver and an authoritative nameserver are both DNS servers, for example, but they perform different jobs.

DNS examples and use cases

DNS supports more than loading websites: Applications and network services use different DNS records and resolution processes to locate resources.

Loading a website

When someone enters a website's domain into a browser, DNS helps locate the IP address associated with that name. Once the address is returned, the browser can connect to the appropriate destination.

Routing email

DNS also helps email systems determine where messages should go. MX records specify the mail servers responsible for accepting email for a domain.

Changing infrastructure

An organization may move a website or service to infrastructure with a different IP address while keeping the same domain name. Updating the relevant DNS record allows future lookups to direct traffic toward the new address once applicable cached records expire.

Supporting security monitoring

DNS requests can also provide context about network behavior. For example, a device repeatedly querying an unexpected domain may warrant investigation when that activity appears alongside other suspicious signals.

This makes DNS data one useful source of network telemetry that defenders can correlate with other network and security information.

How DNS fits into security operations

DNS was designed to help systems locate resources, but attackers can also manipulate or misuse DNS. Security teams therefore examine DNS activity alongside other sources of network data. Some common DNS-related security concerns include:

  • DNS spoofing or cache poisoning: False DNS information can cause a request to resolve to an unintended IP address.
  • DNS tunneling: An attacker can encode information in DNS queries and responses to create a covert communication channel.
  • Malicious domains: Malware, phishing infrastructure, and command-and-control (C2) systems may rely on domains that produce identifiable DNS activity.
  • Abnormal DNS behavior: Unusual query frequency, unexpected destinations, or other patterns may provide context during an investigation.

DNS activity alone doesn’t establish that malicious behavior has occurred. Its value increases when teams correlate it with other evidence, such as endpoint activity, authentication events, and network connections.

For that reason, DNS can contribute to network traffic analysis (NTA) and network detection and response (NDR). These disciplines use network activity to help teams identify, investigate, and respond to suspicious behavior.

DNS security also overlaps with threats that manipulate communications between systems. Man-in-the-middle attacks (MITM), for example, involve an attacker positioning themselves between communicating parties to intercept or alter information.

Author

Aaron Wells
Aaron Wells

Frequently asked questions