DNS
The Internet's Domain Name System (DNS) performs hostname-to-IP-address translation:
- hostnames are for humans (mnemonic)
- IP addresses are used for machines (fixed-length, hierarchically structured)
It's a complex system:
The DNS is two things
- a distributed database implemented in a hierarchy of DNS servers
- that links domain names to IP addresses
- DNS servers are often UNIX machines running the Berkeley Internet Name Domain (BIND) software
- an application-layer protocol that allows hosts to query the distributed database
- since it runs between end systems using the client-server paradigm and relies on an underlying end-to-end transport protocol to transfer DNS messages
- DNS primarily runs over UDP and uses port 53, but also uses TCP/53 for large responses, DNSSEC, and zone transfers
- DNS can also use encrypted transports such as DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT)
The DNS hierarchy and distributed database
The DNS has a hierarchical structure:
Root zone → TLDs → Domains → Subdomains
Each part or namespace of a domain name comes with its own zone of administrative control.
For en.wikipedia.org.:
| Namespaces of the domain name | en = hostname |
.wikipedia = second-level name |
.org = top-level name |
. = root (usually hidden) |
|---|---|---|---|---|
| Zone | Subdomain zone(s) | Domain zone | Top-level domain (TLD) zone | Root zone |
| Administrator | Domain owners | Registrars | Registries/TLD operators | Internet Corporation for Assigned Names and Numbers (ICANN) |
| Administrative control |
A domain owner can create and manage subdomains (and deeper levels), but they are responsible for maintaining the records for anything under their domain.
These subdomains aren't sold separately, only the main domain is registered. |
Individuals or organizations can purchase a domain name through accredited registrars approved by ICANN.
The buyer becomes the registrant. |
Domains are divided into generic TLDs and country-code TLDs.
Each TLD is managed by a registry. |
The root zone is coordinated by ICANN/IANA and served by globally distributed root server operators.
These servers coordinate all top-level domains and are distributed and redundant (13 logical root server systems globally). |
The three classes of DNS servers:
- root DNS servers
- more than 1000 root servers instances scattered all over the world
- copies of 13 different root servers
- top-level domain (TLD or ccTLD) DNS servers
- for each TLD there is a TLD server (or a server cluster)
- the network infrastructure supporting a TLD can be large and complex
- authoritative DNS servers
- the final server that stores and provides the definitive answers for the domain you are looking for
Another important type of DNS server is the local DNS server:
- does not strictly belong to the hierarchy of servers
- but is nevertheless central to the DNS architecture
- each ISP has one or more local DNS servers (or default name servers)
- when a host makes a DNS query:
- the query is sent to the local DNS server
- which acts as a proxy
- and forwards the query into the DNS server hierarchy
Root DNS servers
Throughout the years, DDoS attacks have targeted the DNS itself.
On October 21, 2002, a denial of service attack lasting one hour targeted all of the DNS root servers in operation at the time.
The assault on the Internet's core infrastructure attracted considerable attention and, since then, the DNS has become distributed and engineered to achieve site mirroring, load balancing, and replication.
How DNS works
From the perspective of an invoking application in the user's host, DNS is a black box:
- the application invokes the client side of DNS with the hostname that needs to be translated
- the client side of DNS sends a query message into the network (UDP datagrams, port 53)
- after a delay, the client side of DNS receives a DNS reply message with the desired mapping
- the mapping is passed to the invoking application
This is what happens when a client makes a DNS query to determine the IP address for the hostname www.amazon.com:
| Step | Message | Action |
|---|---|---|
| 1 | query 1 |
the client sends a DNS query to its local DNS server with the hostname to be translated |
| 2 | query 2 |
the local DNS server forwards the query to a root DNS server |
| 3 | reply 1 |
the root DNS server returns IP addresses for TLD servers for the top-level domain com |
| 4 | query 3 |
the local DNS server contacts one of these TLD servers |
| 5 | reply 2 |
the TLD server returns the IP address of an authoritative server for amazon.com |
| 6 | query 4 |
the local DNS server contacts one of the authoritative servers for amazon.com |
| 7 | reply 3 |
the authoritative DNS server returns the IP address for the hostname amazon.com |
| 8 | reply 4 |
the local DNS server responds to the client with the IP address |
In general:
- the TLD server doesn't know the authoritative DNS server for the hostname
- may know only of an intermediate DNS server, which in turn knows the authoritative DNS server for the hostname
DNS queries
DNS resolution queries can be:
-
recursive
- the client sends a single request to a DNS resolver with the
RD(Recursion Desired) bit set - by doing this, the client delegates the entire lookup process to the resolver
- the resolver then queries the DNS hierarchy on the client's behalf and returns the final answer
- the term recursive describes the resolver's behavior internally: it follows referrals, resolves intermediate sub-problems, and continues until it reaches an authoritative answer, similar to recursion in computer science
- from the client's perspective, only one request is sent, even though many DNS queries may occur behind the scenes
- the client sends a single request to a DNS resolver with the
-
iterative
- the server just returns a referral to the next server to ask
- the client is then responsible for following the chain itself
These two modes exist for architectural reasons:
- root and TLD servers stay scalable by responding iteratively rather than doing downstream work
- recursive resolvers can cache results for many clients at once
- authoritative servers often refuse recursive queries to avoid being abused as amplification vectors
In practice, recursive queries are typically used by clients such as laptops, browsers, and phones, because end-user devices do not need to understand the whole DNS hierarchy.
Recursive resolvers centralize that complexity. They accept recursive queries from clients, then use iterative queries to walk the DNS hierarchy:
- first querying a root server
- then a TLD server
- and finally an authoritative server
DNS caching
Because DNS adds an additional delay (sometimes substantial, from ms to seconds) to the Internet applications that use it, it extensively exploits DNS caching to improve performance:
- when a DNS server receives a DNS reply, it can cache the mapping in its local memory
- a DNS server can provide a cached IP address, even if it is not authoritative for the hostname
- because hosts and mappings aren't permanent, DNS servers discard cached information after a period of time (TTL values vary widely depending on the record and DNS configuration)
DNS records
The DNS servers that together implement the DNS distributed database store resource records (RRs).
A resource record is a four-tuple (Name, Value, Type, TTL) where TTL is the Time To Live of the resource record (how long a DNS record is cached before it must be refreshed).
| Field / Type | Description | Name | Value | Example |
|---|---|---|---|---|
|
Standard hostname-to-IP address mapping.
|
|
|
|
|
Used to route DNS queries further along in the query chain.
|
|
|
|
|
Provides querying hosts the canonical name for a hostname (the "real" machine name).
|
|
|
|
|
Allows hostnames of mail servers to have simple aliases for email routing.
|
|
|
|
If a DNS server:
- is authoritative for a particular hostname, then the DNS server will contain a Type A record for the hostname
- is not authoritative for a hostname, then the server will contain a Type NS record for the domain that includes the hostname
DNS load balancing
DNS can be used to perform load distribution among replicated Web servers:
- a set of IP addresses is associated with one alias hostname
- the DNS database contains this set of IP addresses
- when clients make a DNS query for a name mapped to a set of addresses:
- the server responds with the entire set of IP addresses
- but rotates the ordering of the addresses within each reply
Inserting records into the DNS database
You need to register a domain name at a registrar.
A registrar is a commercial entity that:
- verifies the uniqueness of the domain name
- enters the domain name into the DNS database
- collects a fee from you for its services
- prior to 1999, a single registrar (Network Solutions) had a monopoly on domain name registration for
com,net, andorgdomains - now there are many registrars accredited by the Internet Corporation for Assigned Names and Numbers (ICANN)
When you register a domain name with some registrar, you need to provide the names and IP addresses of your primary and secondary authoritative DNS servers:
- suppose the names and IP addresses are
dns1.networkutopia.com/212.2.212.1dns2.networkutopia.com/212.212.212.2
- for each of these two authoritative DNS servers, the registrar enters a Type
NSand a TypeArecord into the TLD com servers - e.g. for the primary authoritative server for
networkutopia.com, the registrar would insert the following two resource records into the DNS system:(networkutopia.com, dns1.networkutopia.com, NS)(dns1.networkutopia.com, 212.212.212.1, A)
Structure of a DNS packet
DNS has query and reply messages. They have the same format.
| Domain Name System (DNS) | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Offsets | Octet | 0 | 1 | 2 | 3 | ||||||
| Octet | Bit | 0-7 | 8-15 | 16-23 | 24-31 | ||||||
| 0 | 0 | DNS ID Number | QR | OpCode | AA | TC | RD | RA | Z | RCode | |
| 4 | 32 | Question Count | Answer Count | ||||||||
| 8 | 64 | Name Server (Authority) Record Count | Additional Records Count | ||||||||
| 12+ | 96+ | Questions Section | Answers Section | ||||||||
| Authority Section | Additional Information Section | ||||||||||
QR: Query/ResponseAA: Authoritative AnswersTC: TruncationRD: Recursion DesiredRA: Recursion AvailableZ: ReservedRCode: Response Code