Free tools Windows power users keep installed
One-click scans. No signup required.
The Domain Name System (DNS) is the Internet’s hierarchical, distributed naming system. It lets software use human-readable names such as www.example.com to obtain typed information about those names, including host address information. DNS is more than a simple hostname-to-IP table: its resource records can describe several kinds of technical data, stored across cooperating name servers.
What does DNS do in simple terms?
DNS is a directory organized as a tree. A client supplies a name and a record type to a resolver, and the resolver obtains the matching resource record. For a website, that record commonly provides address information so a client can connect to the host. Other record types support other functions, such as directing mail or identifying services.
The tree is shared as one namespace, but its data is distributed among many servers and administrative organizations. This design allows names to remain usable across different hosts, networks, protocol families and internets.
How does DNS resolve a website name?
When a client needs information for a name such as www.example.com, the normal process is:
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
- The client asks a resolver. An application or operating system sends the name and requested record type to a local or recursive resolver.
- The resolver checks what it already knows. It can use cached information that is still valid. If the needed answer is available, it returns the result without walking the hierarchy again.
- The resolver queries the hierarchy when necessary. If it does not have the answer, it contacts a known name server and follows referrals.
- The root level identifies the relevant top-level domain. For
www.example.com, a root server refers the resolver to the servers responsible for.com. - The TLD level identifies the domain’s authoritative servers. A
.comserver refers the resolver to the authoritative name servers forexample.com. - The authoritative server returns the requested record. The server responsible for the relevant zone supplies the address or other data for
www.example.com. - The resolver answers the client and may cache the result. Later clients can receive the cached data until it is no longer valid.
The client generally sees one answer from its resolver; the resolver performs the referral work on the client’s behalf.
What are the main DNS building blocks?
Domain name space
The name space is a tree of labels. The root is at the top, followed by top-level domains such as .com, then domains such as example.com, and names beneath them such as www.example.com.
Resource records
A resource record is typed data attached to a name. The query’s record type tells the resolver what information is wanted, so DNS can carry more than host addresses.
Name servers and zones
Name servers store DNS data. An authoritative name server is responsible for a particular zone—the portion of the name space delegated to it—and is the source of authority for records in that zone.
Recommended Free Tools
Rank #3
Resolvers
A resolver obtains answers for clients. A recursive resolver can check its cache, query other servers and follow referrals until it can return a result or report that one cannot be obtained.
Recursive and authoritative DNS servers: what is the difference?
| Aspect | Recursive resolver | Authoritative name server |
|---|---|---|
| Primary role | Obtains an answer for a client, including by querying other servers. | Publishes the records for a zone it serves. |
| Typical answer source | A cached result or data gathered through referrals. | The zone’s authoritative data. |
| Operational control | Managed for the clients or network using the resolver. | Managed by the organization responsible for the domain’s zone. |
| Relationship to a domain | May answer questions about many domains; answering does not make it authoritative for them. | Is responsible only for the zones delegated to it. |
| DNSSEC role | Can validate signed data and delegations on behalf of clients. | Publishes the zone data and, where deployed, its DNSSEC signing material. |
A public recursive resolver is therefore not authoritative for a domain merely because it can answer a query about that domain.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What do DNS records do?
Records attach specific, typed information to names. Address records can tell a resolver where a host can be reached; other types can describe mail handling, aliases, service locations or text-based policy and verification data. The record type is essential: asking for one type does not request every kind of information stored for the name.
Because records are held in zones and may be cached by recursive resolvers, a change made at an authoritative server is not necessarily visible everywhere immediately; resolvers can continue using a cached answer until it expires according to the zone’s settings.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- Used Book in Good Condition
Is DNSSEC the same as DNS encryption?
No. Ordinary DNS supplies a distributed lookup mechanism. DNSSEC adds authentication and integrity checking: a zone publishes a public key and signed data, while a validating recursive resolver checks the signatures and the chain of keys and delegations from the parent zone.
A successful DNSSEC validation gives the resolver evidence that the returned DNS data came from the expected zone and was not altered in transit. DNSSEC does not, by itself, encrypt the DNS query or hide the name being requested. Validation and confidentiality are separate properties.
Why is DNS distributed and hierarchical?
No single server needs to hold every name. The root, TLD and authoritative levels divide responsibility, while recursive resolvers and caches reduce repeated work for clients. Delegation lets the organization responsible for a domain operate its own authoritative zone without requiring the root or TLD servers to store every record beneath that domain.
Quick Recap
What should you remember about DNS?
- DNS maps names to typed resource records, not only IP addresses.
- The namespace is hierarchical, with root, TLD and authoritative levels.
- A resolver performs lookups for clients, follows referrals and can use cached answers.
- Authoritative servers are responsible for specific zones; recursive resolvers are answer-finding intermediaries.
- DNSSEC validates origin and integrity through signatures and a chain of trust, but it is not DNS query encryption.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




