DNS

The Internet's Domain Name System (DNS) performs hostname-to-IP-address translation:

It's a complex system:

The DNS is two things

  1. a distributed database implemented in a hierarchy of DNS servers
    • that links domain names to IP addresses
    • DNS servers are often UNIX machines running the Berkeley Internet Name Domain (BIND) software
  2. an application-layer protocol that allows hosts to query the distributed database
    • since it runs between end systems using the client-server paradigm and relies on an underlying end-to-end transport protocol to transfer DNS messages
    • DNS primarily runs over UDP and uses port 53, but also uses TCP/53 for large responses, DNSSEC, and zone transfers
    • DNS can also use encrypted transports such as DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT)

The DNS hierarchy and distributed database

The DNS has a hierarchical structure:

Root zone → TLDs → Domains → Subdomains

Each part or namespace of a domain name comes with its own zone of administrative control.

For en.wikipedia.org.:

Namespaces of the domain name en = hostname .wikipedia = second-level name .org = top-level name . = root (usually hidden)
Zone Subdomain zone(s) Domain zone Top-level domain (TLD) zone Root zone
Administrator Domain owners Registrars Registries/TLD operators Internet Corporation for Assigned Names and Numbers (ICANN)
Administrative control A domain owner can create and manage subdomains (and deeper levels), but they are responsible for maintaining the records for anything under their domain.
These subdomains aren't sold separately, only the main domain is registered.
Individuals or organizations can purchase a domain name through accredited registrars approved by ICANN.
The buyer becomes the registrant.
Domains are divided into generic TLDs and country-code TLDs.
Each TLD is managed by a registry.
The root zone is coordinated by ICANN/IANA and served by globally distributed root server operators.
These servers coordinate all top-level domains and are distributed and redundant (13 logical root server systems globally).

The three classes of DNS servers:

  1. root DNS servers
    • more than 1000 root servers instances scattered all over the world
    • copies of 13 different root servers
  2. top-level domain (TLD or ccTLD) DNS servers
    • for each TLD there is a TLD server (or a server cluster)
    • the network infrastructure supporting a TLD can be large and complex
  3. authoritative DNS servers
    • the final server that stores and provides the definitive answers for the domain you are looking for

Another important type of DNS server is the local DNS server:

Root DNS servers

Throughout the years, DDoS attacks have targeted the DNS itself.

On October 21, 2002, a denial of service attack lasting one hour targeted all of the DNS root servers in operation at the time.

The assault on the Internet's core infrastructure attracted considerable attention and, since then, the DNS has become distributed and engineered to achieve site mirroring, load balancing, and replication.

How DNS works

From the perspective of an invoking application in the user's host, DNS is a black box:

This is what happens when a client makes a DNS query to determine the IP address for the hostname www.amazon.com:

Step Message Action
1 query 1 the client sends a DNS query to its local DNS server with the hostname to be translated
2 query 2 the local DNS server forwards the query to a root DNS server
3 reply 1 the root DNS server returns IP addresses for TLD servers for the top-level domain com
4 query 3 the local DNS server contacts one of these TLD servers
5 reply 2 the TLD server returns the IP address of an authoritative server for amazon.com
6 query 4 the local DNS server contacts one of the authoritative servers for amazon.com
7 reply 3 the authoritative DNS server returns the IP address for the hostname amazon.com
8 reply 4 the local DNS server responds to the client with the IP address

In general:

DNS queries

DNS resolution queries can be:

  1. recursive

    • the client sends a single request to a DNS resolver with the RD (Recursion Desired) bit set
    • by doing this, the client delegates the entire lookup process to the resolver
    • the resolver then queries the DNS hierarchy on the client's behalf and returns the final answer
    • the term recursive describes the resolver's behavior internally: it follows referrals, resolves intermediate sub-problems, and continues until it reaches an authoritative answer, similar to recursion in computer science
    • from the client's perspective, only one request is sent, even though many DNS queries may occur behind the scenes
  2. iterative

    • the server just returns a referral to the next server to ask
    • the client is then responsible for following the chain itself

These two modes exist for architectural reasons:

In practice, recursive queries are typically used by clients such as laptops, browsers, and phones, because end-user devices do not need to understand the whole DNS hierarchy.

Recursive resolvers centralize that complexity. They accept recursive queries from clients, then use iterative queries to walk the DNS hierarchy:

DNS caching

Because DNS adds an additional delay (sometimes substantial, from ms to seconds) to the Internet applications that use it, it extensively exploits DNS caching to improve performance:

DNS records

The DNS servers that together implement the DNS distributed database store resource records (RRs).

A resource record is a four-tuple (Name, Value, Type, TTL) where TTL is the Time To Live of the resource record (how long a DNS record is cached before it must be refreshed).

Field / Type Description Name Value Example

Type=A

Standard hostname-to-IP address mapping.

  • Name is a hostname

  • Value is the IP address for the hostname

relay1.bar.foo.com

145.37.93.126

(relay1.bar.foo.com, 145.37.93.126, A)

Type=NS

Used to route DNS queries further along in the query chain.

  • Name is a domain (such as foo.com)

  • Value is the hostname of an authoritative DNS server that knows how to obtain the IP addresses for hosts in the domain

foo.com

dns.foo.com

(foo.com, dns.foo.com, NS)

Type=CNAME

Provides querying hosts the canonical name for a hostname (the "real" machine name).

  • Name is the alias hostname

  • Value is the canonical hostname

foo.com

relay1.bar.foo.com

(foo.com, relay1.bar.foo.com, CNAME)

Type=MX

Allows hostnames of mail servers to have simple aliases for email routing.

  • Name is the alias hostname

  • Value is the canonical name of a mail server

foo.com

mail.bar.foo.com

(foo.com, mail.bar.foo.com, MX)

If a DNS server:

DNS load balancing

DNS can be used to perform load distribution among replicated Web servers:

Inserting records into the DNS database

You need to register a domain name at a registrar.

A registrar is a commercial entity that:

When you register a domain name with some registrar, you need to provide the names and IP addresses of your primary and secondary authoritative DNS servers:

Structure of a DNS packet

DNS has query and reply messages. They have the same format.

Domain Name System (DNS)
Offsets Octet 0 1 2 3
Octet Bit 0-7 8-15 16-23 24-31
0 0 DNS ID Number QR OpCode AA TC RD RA Z RCode
4 32 Question Count Answer Count
8 64 Name Server (Authority) Record Count Additional Records Count
12+ 96+ Questions Section Answers Section
Authority Section Additional Information Section

Previous E-mail All ⏎ Next Peer-to-peer file distribution

A Kemar Joint