DNS gets described as "the internet's phone book," which captures the basic idea — turning names into addresses — but misses the important part: it's not one book, it's a distributed system with no single central server anyone queries directly.

Why "distributed" matters

No single server holds every domain's records. Instead, DNS is organized hierarchically: root servers know where to find top-level domain (like .com or .org) servers, which know where to find the specific authoritative servers for each domain, which finally hold the actual records. A lookup for a specific domain typically involves following this chain, though caching at every level means most everyday lookups are answered quickly from nearby cached data rather than walking the full hierarchy each time.

The basic lookup flow

  1. Your device asks a recursive resolver (usually run by your ISP, or a public service you've configured) to look up a name.
  2. If the resolver doesn't already have a cached answer, it queries the hierarchy — root, then top-level domain servers, then the domain's own authoritative servers — to find the answer.
  3. The resolver returns the answer to your device and typically caches it for a period defined by the record's TTL (time to live).

Why this design matters for privacy and reliability

Because DNS relies on a resolver acting on your behalf, whichever resolver you use can observe every domain you look up — this is the basis for both DNS privacy concerns (see DNS Privacy) and DNS leaks (see DNS Leaks Explained), where a VPN's protection can be undermined if DNS queries take a different path than expected.

FAQ

Is DNS the same as a URL?

No — DNS translates a domain name (like example.com) into an IP address; a URL includes additional information like the specific path and protocol on top of the domain.