WEBINVEST.IT
Glossary

DNS

DNS, Domain Name System, is the distributed system that associates human-readable names such as example.it with data used by computers and applications. Its most well-known function is resolving IP addresses to connect to a service, but DNS can also publish information about mail servers, nameservers, service checks, security policies, and other parameters. It is not a single centralized database: it is a hierarchy of zones managed by different authorities and queried through resolvers. When a user types a domain name, the browser or operating system may query a resolver, which retrieves or reuses DNS data according to cache rules.

The hierarchy starts at the root, continues with top-level domains such as .it or .com, and extends to registered names and subdomains. A registry maintains delegations for its TLD; the domain owner or their providers manage the domain zone. The registrar is the entity managing the registration relationship, while a DNS provider may host the zone and respond to authoritative queries. These roles can be fulfilled by different companies. Registering a domain does not automatically configure the website, email, or DNS records: correct nameserver delegation and proper data setup are required.

Records, Queries, and Cache

A DNS zone contains various record types. An A record maps a name to an IPv4 address; AAAA to IPv6; MX specifies mail servers; CNAME creates an alias to another name; NS indicates nameservers; TXT may contain verifications or policies. The resolver follows delegations and sends queries to appropriate servers, then returns the response to the client. TTL defines how long a response can be cached, but does not guarantee exact global propagation timing. Different caches may update at different times, and changes should be verified by querying relevant resolvers and authoritative servers.

DNS is essential for availability and continuity. A misconfigured record can make a website unreachable, interrupt email, or redirect traffic to the wrong system. Before changing nameservers, export the existing zone and compare web records, MX, SPF, DKIM, DMARC, checks, and subdomains. Nameserver migration does not automatically copy records: the new zone must be ready before delegation. Even a correct record may have no effect if the domain is expired, the delegation is incorrect, or resolvers are using outdated cache.

Security and Reliability

DNSSEC adds digital signatures that allow validating resolvers to verify the integrity and authenticity of signed DNS data. It does not encrypt queries nor replace TLS, strong passwords, or account protection. Open DNS resolvers or misconfigured authoritative servers can be abused, while registrar or DNS provider account theft may enable harmful changes. Enabling multi-factor authentication, limited roles, change logs, and approval processes for critical records is advisable. In enterprise environments, nameserver redundancy and monitoring help detect failures, but configuration consistency remains key.

When diagnosing issues, distinguish DNS from application and network problems: check if the name resolves, which record is returned, what address is reached, and whether the service responds. A browser "DNS error" may stem from missing data, broken delegation, cache, or local configuration. Understanding records, TTL, registrar, registry, authoritative nameservers, and resolvers helps locate the failure point. In summary, DNS is the hierarchical infrastructure that publishes and distributes information needed to locate Internet services. It is essential but distinct from hosting, website, or domain registration.

← Full glossary