How DNS works: what happens when you type a URL
You type a URL, and the page loads. Between those two moments, a machine-readable address had to be found, and a small system-wide search ran to find it. That system is the Domain Name System (DNS), and it's worth understanding because every deployment, proxy, and certificate ultimately depends on it.
Computers don't recognize names like example.com. They connect using IP addresses. DNS is the layer that maps human-readable names to those addresses, so nobody has to memorize a string of digits to visit a site.
The lookup sequence
When you hit Enter, the search starts close to home and works outward:
- Browser cache. Your browser checks whether it already resolved this name recently. Most requests never get past this step.
- OS cache and hosts file. If the browser misses, your operating system's resolver checks its own cache and the local
hostsfile. That's how you can pin a domain to a specific IP on one machine. - Recursive resolver. Failing both local caches, your computer sends a query to a recursive resolver, usually run by your ISP, a company like Cloudflare, or a service such as Google Public DNS.
- Root servers. If the resolver has nothing cached, it asks a root server. The root doesn't know the answer; it points the resolver toward the right top-level domain (TLD) server, such as
.com. - TLD servers. The
.comTLD server doesn't hold example.com's records either. It points the resolver to the domain's authoritative nameserver. - Authoritative nameserver. This is the source of truth. It holds the actual records and returns the answer, which the resolver passes back to your browser.
For example.com that final answer is often an IPv4 address such as 104.20.23.154 (at the time of writing), which your browser then connects to.
Record types you'll meet
DNS stores different kinds of records for different jobs:
- A maps a name to an IPv4 address.
example.com A 104.20.23.154. - AAAA does the same for IPv6 addresses. It's the same job, over the newer address space.
- CNAME creates an alias to another name.
www.github.comis a CNAME pointing togithub.com. - MX tells mail servers where a domain's email goes, with a priority number. gmail.com uses hosts like
gmail-smtp-in.l.google.com. - TXT holds arbitrary text, often used for verification and email anti-spam checks like SPF and DKIM.
- NS announces which nameservers are authoritative for a domain, for example
hera.ns.cloudflare.comandelliott.ns.cloudflare.comfor example.com at the time of writing.
TTL and caching
Every record carries a TTL (time to live): the maximum number of seconds a resolver may reuse an answer without asking again. It's a ceiling, not a promise. A longer TTL means faster lookups because more caches stay warm, but it also means a DNS change takes longer to reach users. That's the real engine behind made-up "DNS propagation" timelines. Lower the TTL before you change records, and the new value lands in minutes.
Try it yourself
Both dig and nslookup are standard DNS lookup tools, installed on most systems. Open a terminal and run:
