DNS, explained: how a domain name actually becomes an IP address
The one-sentence version
DNS is a distributed, cached lookup system: when you ask for a name like example.com, your computer doesn't ask one all-knowing server — it asks a chain of servers, each of which only knows one small piece of the answer, until the final piece resolves to an actual IP address.
The four servers in every fresh lookup
- Recursive resolver — the one your OS actually talks to (often run by your ISP, or a public one like 1.1.1.1). It does the legwork on your behalf.
- Root server — knows nothing about example.com specifically, but knows which server handles every ".com" domain.
- TLD server — knows nothing about example.com's actual content, but knows which server is authoritative for it.
- Authoritative server — the only one that actually holds the real answer: "example.com is at 93.184.216.34."
The concrete walkthrough, hop by hop
The resolver asks the root server ("where's .com handled?"). The root replies with the TLD server's address. The resolver asks that TLD server ("where's example.com specifically?"). The TLD server replies with the authoritative server's address. The resolver finally asks the authoritative server and gets the real IP back — then hands it to your browser. Four round trips for a lookup that "feels instant," which is only true because of caching.
Why it usually feels instant anyway: caching and TTL
Every DNS answer carries a TTL (time to live). The resolver caches that answer for exactly that duration and skips the whole four-hop chain on repeat lookups. This is also exactly why DNS changes — like pointing a domain at a new server — don't take effect everywhere instantly. Every resolver out there keeps serving its cached answer until that specific TTL expires, wherever it happens to be in its countdown.
What people get wrong
"Clearing my browser cache will fix a DNS problem" — browser cache and DNS cache are different things, living at different layers (browser, operating system, resolver, ISP). Clearing your browser's cache does absolutely nothing to a stale DNS entry sitting in your OS's resolver or your ISP's.
One caveat worth knowing
DNS answers usually aren't cryptographically verified by default — that protection (DNSSEC) exists but isn't universally deployed — which is exactly why DNS spoofing and cache poisoning are real, historically significant attack categories worth knowing exist, rather than an abstract textbook worry.