All about Protocols

DNS — The Phonebook That Isn't

https://toolkit.whysonil.dev/how-it-works/dns/

DNS | Networking | Protocols | Security

WhySoNil's DNS guide explains DNS as the internet's distributed "phonebook", designed for speed and scale.

It covers transport (UDP on port 53 with TCP fallback), namespace delegation (root → TLD → authoritative), and the importance of caching and TTL.

It details zone files, common record types (A, AAAA, CNAME, MX, TXT, NS, SOA, CAA, SRV), and glue records.

It explains performance and resilience techniques such as anycast and multi-layer caching.

It summarizes security: DNSSEC for integrity and DoT/DoH/DoQ for encrypted transport, with practical trade-offs.

It includes practical debugging commands and tools (dig, dig +trace, dig +dnssec, nslookup, dog) and pointers to DNSViz and intoDNS for visualization.

Key takeaways:

  • DNS is optimized for small, fast UDP queries; TCP is the fallback for large responses.
  • TTL-driven caching scales DNS but requires careful TTL management during changes.
  • DNSSEC provides integrity, not privacy; DoH/DoT/DoQ add privacy but shift trust to providers.
  • Use dig and dig +trace to diagnose delegation, caching, and DNSSEC issues.

The page also includes a short self-check quiz and links to RFCs and Cloudflare learning for further reading.