What Is DNS and How Does It Work?
What is DNS and how does it work? DNS (Domain Name System) helps an app find the IP address for a hostname such as loqmi.com. Your device asks a recursive resolver, which may answer from cache or follow referrals from the root and top-level-domain servers to the domain's authoritative nameserver; only then does the browser connect.
What is DNS and how does it work?
DNS is not the website or the internet connection. People use names such as www.example.com; network software uses records describing where a service can be found. DNS can return addresses, mail destinations, aliases, verification text, and other service information.
In www.example.com, com is the top-level domain, example the registered domain, and www a host label. The architecture and record format are defined in RFC 1034 and RFC 1035.
| Record | What it tells DNS | Typical use |
|---|---|---|
| A | An IPv4 address | Points a hostname to an IPv4 service. |
| AAAA | An IPv6 address | Points a hostname to an IPv6 service. |
| CNAME | Another hostname | Creates an alias; it does not directly contain an IP address. |
| MX | Mail servers and preference | Helps email systems find where to deliver mail. |
| NS | Authoritative nameservers | Delegates a zone to the servers that publish its records. |
| TXT | Text data | Commonly used for verification and email policies. |
How a DNS lookup works step by step
When an app needs www.example.com, it normally talks to the device's stub resolver, not a root server. A cold lookup is the useful model; a cache hit can skip most steps.
- Check local information. The app or operating system may have an answer in cache, or a hosts file may override public DNS.
- Ask a recursive resolver. Your router, ISP, workplace, VPN, or chosen DNS service can provide it; it checks its own cache first.
- Ask the root. If needed, the resolver asks which nameservers handle the top-level domain, such as
com. The root normally returns a referral, not the website address. - Ask the TLD nameserver. The
comservice refers the resolver to the authoritative nameservers forexample.com. - Ask the authoritative nameserver. It returns the record, an alias, or an error. The resolver caches the result and sends it to your device.
- Connect to the result. The browser uses the address to start the web connection. HTTPS, TCP or QUIC, and the application protocol handle what follows.
Caching, TTL, and why changes take time
Each resource record carries a TTL (time to live): how long a cache may reuse the answer before asking again. Caches can exist in an app, operating system, router, recursive resolver, or network service, so devices can temporarily receive different answers after a change.
Negative answers can be cached too. RFC 2308 describes caching information that a name or record does not exist. A new record may therefore take time to appear, and flushing your cache cannot force a remote resolver to forget. See DNS TTL explained.
Common DNS failures: symptom, cause, next check
A DNS error is evidence about name resolution, not a complete diagnosis of your connection. Use the exact error and whether one site or every site fails to choose the next test.
| Symptom | Possible cause | Next check |
|---|---|---|
DNS_PROBE_FINISHED_NXDOMAIN | The resolver says the name does not exist in its current view, or the hostname is mistyped. | Check spelling and record type; compare another network before changing settings. See NXDOMAIN troubleshooting. |
SERVFAIL or timeout | The resolver cannot obtain or validate an answer, or the DNS path is unreachable. | Query the name with nslookup or dig, note the server, and check whether the failure is local or widespread. |
| Only one site fails | A typo, broken delegation, missing record, stale cache, or that site's DNS may be involved. | Test another domain. A new DNS provider cannot fix a record the owner has not published correctly. |
| An old destination appears after a change | A cache still has time remaining, or the change was made at the wrong provider. | Verify authoritative nameservers, then wait for TTLs and flush only local caches if needed. |
How to check DNS on your device
These paths fit current mainstream versions, but a manufacturer, VPN, work profile, or network tool can override them. Inspect first; change a resolver only when you can undo it.
Windows 11
Open Settings > Network & internet, choose Wi-Fi or Ethernet, then the connected network or Manage known networks. To edit, choose IP assignment > Edit > Manual and use the DNS fields. Microsoft documents this and optional DNS over HTTPS in its Windows network settings guide. ipconfig /all shows servers; nslookup example.com tests a lookup.
macOS
Open Apple menu > System Settings > Network, select the service, then Details > DNS. Apple documents the path in its Mac DNS settings guide. In Terminal, scutil --dns shows configuration and dig example.com queries the system resolver.
Linux
Menus differ by distribution. With systemd-resolved, run resolvectl status for active DNS settings and resolvectl query example.com to test a name; see the resolvectl manual. Otherwise inspect the NetworkManager profile or /etc/resolv.conf.
Android
On stock Android, open Settings > Network & internet > Private DNS, then choose Off, Automatic, or a provider hostname. Labels vary by device, and Private DNS protects only DNS questions and answers; see Google’s Android network settings guide.
iPhone and iPad
For connected Wi-Fi, open Settings > Wi-Fi > Info > Configure DNS. Apple’s iPhone Wi-Fi guide confirms the path. It applies to that Wi-Fi connection; cellular DNS and VPN profiles can differ.
DNS privacy and security: what changes and what does not
Traditional DNS can be visible between your device and resolver. DNS over TLS encrypts that channel, while DNS over HTTPS carries the query inside HTTPS; see RFC 7858 and RFC 8484. The resolver still receives the query, and encryption does not hide the later website connection.
DNSSEC is different: it authenticates signed DNS data but does not provide confidentiality, as RFC 4033 explains. Treat encrypted DNS as one privacy control, not a VPN, malware filter, or substitute for HTTPS and updates.
A quick DNS self-test with Loqmi
- Open Loqmi’s IP tool and note the public IP, ISP, and approximate location. DNS selects names and records; it normally does not change that public IP.
- On Windows, macOS, or Linux, run
nslookup loqmi.comordig loqmi.com. Record the resolver and whether you receive A or AAAA answers. Browser encrypted DNS can differ from command-line behavior. - For a resolver test, change one setting, repeat the lookup, and undo it if worse. Use the DNS-server change guide for device steps.
- Open Loqmi’s speed test before and after to compare connection performance. It cannot prove DNS health or identify an authoritative server.
If a site still fails after the name resolves, investigate the connection, TLS, browser, or application. After a DNS edit, verify the authoritative record before clearing caches; flushing DNS cache is only a local test.
Key takeaways
- DNS maps names to records; your device usually asks a cached recursive resolver before the browser connects.
- A, AAAA, CNAME, MX, NS, and TXT records serve different jobs; a CNAME is an alias, not an IP address.
- TTL and negative caching explain many delayed changes, while NXDOMAIN and SERVFAIL point to different checks.
- DoH, DoT, and DNSSEC improve different properties; none makes every part of browsing private by itself.
Frequently asked questions
What is the difference between a DNS resolver and a DNS server?
DNS server is a broad term for software or a machine that answers DNS questions. A recursive resolver looks up answers for clients and caches them. An authoritative server publishes the records for a zone and answers from that source data. One installation can perform more than one role, but the jobs are different.
Does changing DNS make your internet faster?
It can reduce the time needed to find a site when your current resolver is slow, unreachable, or giving a poor route to its service, but it cannot increase your plan's download or upload capacity. Test the same site and network before and after, and keep the change only if it improves a real problem.
What does DNS_PROBE_FINISHED_NXDOMAIN mean?
It usually means the resolver reported that the requested domain name does not exist in the DNS view it checked. A typo, an unregistered name, a missing record, split DNS, filtering, or stale local information can be involved. Compare the exact hostname and record type before assuming your whole internet connection is down.
Does DNS work with email as well as websites?
Yes. Email systems use DNS records to discover which mail servers accept messages for a domain, while other records can publish sender policies and verification data. DNS does not carry the email itself; it supplies the names and instructions that mail systems use before they connect to an SMTP service.
Sources
- RFC 1034: Domain Names - Concepts and Facilities
- RFC 1035: Domain Names - Implementation and Specification
- RFC 2308: Negative Caching of DNS Queries
- RFC 4033: DNS Security Introduction and Requirements
- RFC 7858: Specification for DNS over TLS
- RFC 8484: DNS Queries over HTTPS
- Microsoft Support: Essential Network Settings and Tasks in Windows
- Android Help: Manage advanced network settings on your Android phone