DNS & Connectivity

What Is DNS and How Does It Work?

What is DNS and how does it work? DNS (Domain Name System) helps an app find the IP address for a hostname such as loqmi.com. Your device asks a recursive resolver, which may answer from cache or follow referrals from the root and top-level-domain servers to the domain's authoritative nameserver; only then does the browser connect.

What is DNS and how does it work?

DNS is not the website or the internet connection. People use names such as www.example.com; network software uses records describing where a service can be found. DNS can return addresses, mail destinations, aliases, verification text, and other service information.

In www.example.com, com is the top-level domain, example the registered domain, and www a host label. The architecture and record format are defined in RFC 1034 and RFC 1035.

RecordWhat it tells DNSTypical use
AAn IPv4 addressPoints a hostname to an IPv4 service.
AAAAAn IPv6 addressPoints a hostname to an IPv6 service.
CNAMEAnother hostnameCreates an alias; it does not directly contain an IP address.
MXMail servers and preferenceHelps email systems find where to deliver mail.
NSAuthoritative nameserversDelegates a zone to the servers that publish its records.
TXTText dataCommonly used for verification and email policies.

How a DNS lookup works step by step

When an app needs www.example.com, it normally talks to the device's stub resolver, not a root server. A cold lookup is the useful model; a cache hit can skip most steps.

  1. Check local information. The app or operating system may have an answer in cache, or a hosts file may override public DNS.
  2. Ask a recursive resolver. Your router, ISP, workplace, VPN, or chosen DNS service can provide it; it checks its own cache first.
  3. Ask the root. If needed, the resolver asks which nameservers handle the top-level domain, such as com. The root normally returns a referral, not the website address.
  4. Ask the TLD nameserver. The com service refers the resolver to the authoritative nameservers for example.com.
  5. Ask the authoritative nameserver. It returns the record, an alias, or an error. The resolver caches the result and sends it to your device.
  6. Connect to the result. The browser uses the address to start the web connection. HTTPS, TCP or QUIC, and the application protocol handle what follows.
The distinction that prevents confusion: a recursive resolver works on your behalf, while an authoritative nameserver publishes the official records for a DNS zone. “DNS server” can refer to either role.

Caching, TTL, and why changes take time

Each resource record carries a TTL (time to live): how long a cache may reuse the answer before asking again. Caches can exist in an app, operating system, router, recursive resolver, or network service, so devices can temporarily receive different answers after a change.

Negative answers can be cached too. RFC 2308 describes caching information that a name or record does not exist. A new record may therefore take time to appear, and flushing your cache cannot force a remote resolver to forget. See DNS TTL explained.

Do not treat “DNS propagation” as a single switch. Before flushing anything, check the authoritative record and the exact hostname. A local flush changes one device; it does not correct a missing record, a bad delegation, or a cached answer held elsewhere.

Common DNS failures: symptom, cause, next check

A DNS error is evidence about name resolution, not a complete diagnosis of your connection. Use the exact error and whether one site or every site fails to choose the next test.

SymptomPossible causeNext check
DNS_PROBE_FINISHED_NXDOMAINThe resolver says the name does not exist in its current view, or the hostname is mistyped.Check spelling and record type; compare another network before changing settings. See NXDOMAIN troubleshooting.
SERVFAIL or timeoutThe resolver cannot obtain or validate an answer, or the DNS path is unreachable.Query the name with nslookup or dig, note the server, and check whether the failure is local or widespread.
Only one site failsA typo, broken delegation, missing record, stale cache, or that site's DNS may be involved.Test another domain. A new DNS provider cannot fix a record the owner has not published correctly.
An old destination appears after a changeA cache still has time remaining, or the change was made at the wrong provider.Verify authoritative nameservers, then wait for TTLs and flush only local caches if needed.

How to check DNS on your device

These paths fit current mainstream versions, but a manufacturer, VPN, work profile, or network tool can override them. Inspect first; change a resolver only when you can undo it.

Windows 11

Open Settings > Network & internet, choose Wi-Fi or Ethernet, then the connected network or Manage known networks. To edit, choose IP assignment > Edit > Manual and use the DNS fields. Microsoft documents this and optional DNS over HTTPS in its Windows network settings guide. ipconfig /all shows servers; nslookup example.com tests a lookup.

macOS

Open Apple menu > System Settings > Network, select the service, then Details > DNS. Apple documents the path in its Mac DNS settings guide. In Terminal, scutil --dns shows configuration and dig example.com queries the system resolver.

Linux

Menus differ by distribution. With systemd-resolved, run resolvectl status for active DNS settings and resolvectl query example.com to test a name; see the resolvectl manual. Otherwise inspect the NetworkManager profile or /etc/resolv.conf.

Android

On stock Android, open Settings > Network & internet > Private DNS, then choose Off, Automatic, or a provider hostname. Labels vary by device, and Private DNS protects only DNS questions and answers; see Google’s Android network settings guide.

iPhone and iPad

For connected Wi-Fi, open Settings > Wi-Fi > Info > Configure DNS. Apple’s iPhone Wi-Fi guide confirms the path. It applies to that Wi-Fi connection; cellular DNS and VPN profiles can differ.

DNS privacy and security: what changes and what does not

Traditional DNS can be visible between your device and resolver. DNS over TLS encrypts that channel, while DNS over HTTPS carries the query inside HTTPS; see RFC 7858 and RFC 8484. The resolver still receives the query, and encryption does not hide the later website connection.

DNSSEC is different: it authenticates signed DNS data but does not provide confidentiality, as RFC 4033 explains. Treat encrypted DNS as one privacy control, not a VPN, malware filter, or substitute for HTTPS and updates.

A quick DNS self-test with Loqmi

  1. Open Loqmi’s IP tool and note the public IP, ISP, and approximate location. DNS selects names and records; it normally does not change that public IP.
  2. On Windows, macOS, or Linux, run nslookup loqmi.com or dig loqmi.com. Record the resolver and whether you receive A or AAAA answers. Browser encrypted DNS can differ from command-line behavior.
  3. For a resolver test, change one setting, repeat the lookup, and undo it if worse. Use the DNS-server change guide for device steps.
  4. Open Loqmi’s speed test before and after to compare connection performance. It cannot prove DNS health or identify an authoritative server.

If a site still fails after the name resolves, investigate the connection, TLS, browser, or application. After a DNS edit, verify the authoritative record before clearing caches; flushing DNS cache is only a local test.

Key takeaways

  • DNS maps names to records; your device usually asks a cached recursive resolver before the browser connects.
  • A, AAAA, CNAME, MX, NS, and TXT records serve different jobs; a CNAME is an alias, not an IP address.
  • TTL and negative caching explain many delayed changes, while NXDOMAIN and SERVFAIL point to different checks.
  • DoH, DoT, and DNSSEC improve different properties; none makes every part of browsing private by itself.

Frequently asked questions

What is the difference between a DNS resolver and a DNS server?

DNS server is a broad term for software or a machine that answers DNS questions. A recursive resolver looks up answers for clients and caches them. An authoritative server publishes the records for a zone and answers from that source data. One installation can perform more than one role, but the jobs are different.

Does changing DNS make your internet faster?

It can reduce the time needed to find a site when your current resolver is slow, unreachable, or giving a poor route to its service, but it cannot increase your plan's download or upload capacity. Test the same site and network before and after, and keep the change only if it improves a real problem.

What does DNS_PROBE_FINISHED_NXDOMAIN mean?

It usually means the resolver reported that the requested domain name does not exist in the DNS view it checked. A typo, an unregistered name, a missing record, split DNS, filtering, or stale local information can be involved. Compare the exact hostname and record type before assuming your whole internet connection is down.

Does DNS work with email as well as websites?

Yes. Email systems use DNS records to discover which mail servers accept messages for a domain, while other records can publish sender policies and verification data. DNS does not carry the email itself; it supplies the names and instructions that mail systems use before they connect to an SMTP service.

Sources

Related articles