惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Security Affairs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
大猫的无限游戏
大猫的无限游戏
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
爱范儿
爱范儿
阮一峰的网络日志
阮一峰的网络日志
GbyAI
GbyAI
D
Docker
美团技术团队
N
Netflix TechBlog - Medium
罗磊的独立博客
V
Visual Studio Blog
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Hugging Face - Blog
Hugging Face - Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
M
MIT News - Artificial intelligence
腾讯CDC
MongoDB | Blog
MongoDB | Blog
Last Week in AI
Last Week in AI
博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
V
V2EX
L
LangChain Blog
博客园 - 【当耐特】
B
Blog RSS Feed
量子位
U
Unit 42
Engineering at Meta
Engineering at Meta
小众软件
小众软件
宝玉的分享
宝玉的分享
H
Help Net Security
Microsoft Azure Blog
Microsoft Azure Blog
云风的 BLOG
云风的 BLOG
博客园 - 聂微东
博客园 - 司徒正美
The Cloudflare Blog
The GitHub Blog
The GitHub Blog
T
Tailwind CSS Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
The Last Watchdog
The Last Watchdog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
S
SegmentFault 最新的问题
博客园_首页
Attack and Defense Labs
Attack and Defense Labs
TaoSecurity Blog
TaoSecurity Blog
Apple Machine Learning Research
Apple Machine Learning Research
S
Security @ Cisco Blogs

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
The Great DNS Trail
Chris White · 2026-04-27 · via DEV Community

DNS or domain naming system is commonly utilized to allow websites the ability to be represented by a specific name. We'll be looking at the underlying parts of DNS in some detail to see much of what is normally abstracted away.

IP Addresses

In order to understand DNS, it's important to first understand what DNS is mapped to. A domain name by itself can't do anything which is why DNS exists in the first place. The actual means of accessing another system is done through IP addresses. As an example if I ping the dev.to site the address 151.101.66.217 comes back.

Now on the low level IP addresses are a sequences of bytes and the .s are mostly for visual purposes acting much like a comma in a sequences of numbers. If you were to use 32 bit binary the address 151.101.66.217 would come back as 10010111011001010100001011011001. Unlike domain names IP addresses are very compact and streamlined for quick network transport.

IP addresses are also bound by a numbering authority ICANN (Internet Corporation for Assigned Names and Numbers). This authority handles registration of specific IP ranges to corporations. 151.101.66.217 is part of the IP range 151.101.0.0 - 151.101.255.255 which according to ICANN's lookup belongs to the CDN (Content Distribution Network) provider Fastly. Note that there are special ranges of IPs known as private IPs. These sit behind routers and firewalls providing local network functionality.

Hosts File

Now before even touching DNS there's a quick check against what's known as the hosts file. On most systems this lies at /etc/hosts and windows it can be found at C:\Windows\System32\drivers\etc\hosts. The file looks something like this:

# localhost name resolution is handled within DNS itself.
#   127.0.0.1       localhost
#   ::1             localhost
192.168.1.91 rpi
192.168.1.93 rpi2
# End of section

Enter fullscreen mode Exit fullscreen mode

This one is a mapping of my raspberry pi devices to their respective IP addresses on my local network. Instead of typing the IP address I can simply type rpi when SSH-ing in. Unlike actual domain names host file entries are more free form. Some advanced uses have domain names mapped to 0.0.0.0 providing a rudimentary domain blacklist.

DNS Cache

There's another entry point before DNS infrastructure is actually involved and that is DNS cache. Operating systems will vary in how they handle cache. Linux in most cases doesn't have DNS caching on by default due to its need to support a number of different scenarios. On Windows the cache may look something like this:

www.google-analytics.com
----------------------------------------
Record Name . . . . . : www.google-analytics.com
Record Type . . . . . : 1
Time To Live  . . . . : 9
Data Length . . . . . : 4
Section . . . . . . . : Answer
A (Host) Record . . . : 142.250.178.14

Enter fullscreen mode Exit fullscreen mode

Browsers can also have their own built in DNS due to the large number of requests they typically make. Here's an example of my Firefox entry for dev.to:

An excerpt showing the DNS cache entry in Firefox for dev.to

From there caching works up several levels including routers, ISP/public servers, all the way up the chain.

Domain Name Authorities

Domain names have a hierarchical system of authorities starting at what are known as the root servers all the way down to the authoritative server that owns the domain name. This server is generally the registrar used to purchase the domain name.

IANA (Internet Assigned Numbers Authority) is a part of an ICANN affiliate which handles root DNS servers. These servers are the absolute authority on what are known as the top level domains. They keep a listing along with the entity who is authorized to represent the top level domain. For example, VeriSign Global Registry Service is the entity which is authorized to register domain names for the .com top level domain:

.com    generic     VeriSign Global Registry Services

Enter fullscreen mode Exit fullscreen mode

The system also distinguishes between such generic top level domains and ones designated for countries:

.us     country-code    Registry Services, LLC

Enter fullscreen mode Exit fullscreen mode

Most companies will go through the generic top level domain program if they themselves wish to act as an authority. There's also another process for top level domains representing countries. For those who wish to act as a domain registrar instead of a top level authority the accredited registrar program is available. Given how critical DNS infrastructure is all of these applications are strictly vetted so it's certainly a large investment.

The DNS Flow

So assuming the answer to a query of what something like dev.to is mainly starts at the locally designated DNS servers. This will most likely be your ISP but it's not uncommon to utilize public DNS servers such as Quad9, Google, and Cloud Flare. Public DNS servers were popularized after "certain ISPs" decided that showing ad littered pages for unknown domains was a good idea.

So let's say I'm looking for dev.to. Assuming it isn't cached my designated DNS server will reach out to one of the root DNS servers (h.root-servers.net for example) to get information on .to's ownership. .to is country code tld managed by the Kingdom of Tonga. It's not uncommon for country based TLDs to be used for vanity purposes such as .ai. The .to authority (ns01.trs-dns.com as an example) will then delegate the request to the authoritative nameservers which in this case are owned by Cloud Flare who would be considered to be the registrar that dev.to worked with to obtain (or transfer) the domain (josh.ns.cloudflare.com for example). This will then provide a number of responses:

;; ANSWER SECTION:
│dev.to.                 300     IN      A       151.101.194.217
│dev.to.                 300     IN      A       151.101.130.217
│dev.to.                 300     IN      A       151.101.66.217
│dev.to.                 300     IN      A       151.101.2.217

Enter fullscreen mode Exit fullscreen mode

Any of these addresses will allow access to the dev.to site. Sometimes the entry comes back as a CNAME which is essentially an alias to another domain. In this case that will form a new request for the user's designated DNS server. All of these responses will be cached appropriately to ensure timely return to the client.

It's important to note that the user's DNS query to the ISP/Public DNS server is what's known as a recursive query as the server is handling the entire chain for you. The process of the ISP/Public DNS server going root server -> tld server -> authoritative server is known as incremental lookup. Note that if you attempt to query a root name server (recursive by default) it will simply let you know it doesn't support recursive calls and return the incremental version instead.

DNS Packets

DNS utilizes UDP (user datagram protocol) instead of the traditional TCP/IP used by many applications. The UDP protocol is extremely simple with fields for source port, destination port, length of packet, checksum, and data. This avoids the overhead of many of TCP's features which means packets would take longer to return. UDP is generally wrapped around one of the IP protocols to indicate the source and destination IP. DNS packet data is built around messages as defined in RFC 1035. By using the dig DNS tool we can see some of what that looks like:

$ dig dev.to
│; <<>> DiG 9.20.21-1~deb13u1-Debian <<>> dev.to
│;; global options: +cmd
│;; Got answer:
│;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 41311
│;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1
│;; OPT PSEUDOSECTION:
│; EDNS: version: 0, flags:; udp: 4096
│;; QUESTION SECTION:
│;dev.to.                                IN      A
│;; ANSWER SECTION:
│dev.to.                 261     IN      A       151.101.194.217
│dev.to.                 261     IN      A       151.101.66.217
│dev.to.                 261     IN      A       151.101.2.217
│dev.to.                 261     IN      A       151.101.130.217
│
│;; Query time: 0 msec
│;; SERVER: 192.168.1.254#53(192.168.1.254) (UDP)
│;; WHEN: Sun Apr 26 20:17:30 EDT 2026
│;; MSG SIZE  rcvd: 99

Enter fullscreen mode Exit fullscreen mode

Here I'm doing a recursive query directed at my router (which is pointed to Google's DNS servers). The router has indicated it's a server that is capable of doing recursive queries. The answer section is the resulting IPs behind dev.to. Now let's compare this to another query:

$dig @ns01.trs-dns.com dev.to
│; <<>> DiG 9.20.21-1~deb13u1-Debian <<>> @ns01.trs-dns.com dev.to
│; (2 servers found)
│;; global options: +cmd
│;; Got answer:
│;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 61237
│;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 2, ADDITIONAL: 1
│;; WARNING: recursion requested but not available
│;; OPT PSEUDOSECTION:
│; EDNS: version: 0, flags:; udp: 1232
│;; QUESTION SECTION:
│;dev.to.                                IN      A
│;; AUTHORITY SECTION:
│dev.to.                 900     IN      NS      josh.ns.cloudflare.com.
│dev.to.                 900     IN      NS      jill.ns.cloudflare.com.
│
│;; Query time: 91 msec
│;; SERVER: 2620:57:4001::1#53(ns01.trs-dns.com) (UDP)
│;; WHEN: Sun Apr 26 20:03:51 EDT 2026
│;; MSG SIZE  rcvd: 118

Enter fullscreen mode Exit fullscreen mode

In this case dig is letting me know that the server doesn't support recursive queries and I'm given an incremental result instead. Because I'm not given the actual records for the domain in question the "AUTHORITY" section is populated instead pointing me to the authoritative nameservers. When the actual DNS records for the domain name comes back the "ANSWER" records are populated instead.

DNS Records

There are a lot of DNS record types. Which of these will be acted upon will depend on the client accessing the information. A good majority of the time the important records you'll be working with are:

  • A: IPv4 address backing the domain
  • AAA: IPv6 address backing the domain
  • CNAME: points to another host to do DNS lookup for
  • MX: Email server backing the domain's email services
  • TXT: Freeform field used for a number of purposes
  • NS: The authoritative name servers for the domain

A and AA records are the most vital in obtaining the IP address to map to a domain name in a request.

DNSSEC

Being a simple plain text protocol DNS has security issues. If a malicious actor was able to spoof a DNS response that response would be cached among the global DNS infrastructure. This is commonly known as DNS Spoofing or DNS Cache Poisoning.

In an attempt to deal with this DNSSEC was proposed. The system works off of public key cryptography which is the same technology that powers SSL certs. DNS servers use cryptographic signatures to sign their data which are validated by their parent authority (.to's owner in the case of dev.to). The exception being the root DNS servers who have no parent authority. It's why the private keys for the root servers are very well guarded.

It's important to note that DNSSEC support is not mandatory as of right now. Though it's of course recommended to utilize it whenever possible.

Internal DNS

What I've described until now is for the public facing side. Companies are also able to utilize DNS for their own internal domain name resolution. This is done by pointing company equipment at an internal DNS server (or updating network configs for VPN users). The internal server will resolve for internal hosts and generally acts as a proxy if the domain is global such as google.com. Such servers are often hosted with software such as BIND9 on *NIX based systems and the DNS components that are part of Windows Server installs.

Wrap Up

Thanks for joining me in this very long look at the workings of DNS. I hope this proves to be an enlightening experience for those looking to deepen their knowledge on how systems work. It might be useful if you need to debug DNS issues as well!