0 / 4
Name → IP address: A and AAAA
People use names like google.com, but computers talk to each other by IP address. So before connecting, the PC asks a DNS server for that name's IP address. The record type decides what is being asked. A (Address) returns an IPv4 address, and AAAA returns an IPv6 address.
Example: the same name, google.com, is asked once as A and once as AAAA. The values are real lookup results.
1 / 4
My PC → DNS server: ask for the A record
My PC asks for the A record of google.com. It is asking for the IPv4 address linked to the name.
2 / 4
DNS server → my PC: IPv4 address
The DNS server answers with the IPv4 address 142.250.197.46. It has four numbers separated by dots, each 8 bits, so 32 bits in total.
3 / 4
My PC → DNS server: ask for the AAAA record
This time the same name is asked as AAAA. AAAA is the record that gives an IPv6 address.
4 / 4
DNS server → my PC: IPv6 address
The DNS server answers with an IPv6 address. It is written in hexadecimal groups separated by colons, and a run of all-zero groups is shortened to ::. It is 128 bits long. It is four times as long as an IPv4 address, so the record is called AAAA, four A's.
1 / 4
My PC → DNS server: ask for the A record
My PC asks for the A record of www.github.com to find its IPv4 address.
2 / 4
DNS server: check whether it is an alias
The DNS server looks up www.github.com and finds no A record, only a CNAME record. It means, “This name is an alias, and the real name is github.com.”
3 / 4
DNS server: look up the real name once more
The alias alone does not give an IP address. So the DNS server also looks up the A record of the real name, github.com, and gets 20.200.245.247.
4 / 4
DNS server → my PC: answer with both lines
The DNS server returns the alias line and the address line together. My PC connects to 20.200.245.247. A answers with an IP address directly, while CNAME answers with another name that has to be looked up again.
1 / 4
My PC → DNS server: ask for the PTR record
DNS questions are always asked by name. So the numbers of 8.8.4.4 are written in reverse, and in-addr.arpa, a name reserved for reverse lookups, is added to the end. In a domain name the rightmost part (.com) is the widest scope, but in an IP address the leftmost number is. Reversing the numbers puts them in the same order.
2 / 4
DNS server → my PC: name
The DNS server answers that the name of 8.8.4.4 is dns.google.
3 / 4
My PC → DNS server: ask for A in the other direction
Now my PC asks for the A record of the name it received, dns.google. This is the opposite direction from PTR.
4 / 4
DNS server → my PC: IP address
The IPv4 addresses of dns.google are 8.8.8.8 and 8.8.4.4. The IP asked about first is among them, so both directions match. Mail servers sometimes check the other side's IP from both directions like this.
1 / 4
Sending mail server → DNS server: ask for the MX record
The sending mail server takes naver.com, the part after @ in the recipient's address, and asks for its MX record.
2 / 4
DNS server → sending mail server: mail server name
The DNS server answers with the mail server name mx6.mail.naver.com. The 20 in front is the priority; lower numbers are used first. The real answer also lists mx4 and mx5 with priority 20, so mail can go to any of the three.
3 / 4
Sending mail server → DNS server: ask for the A record
An MX answer is a server name, not an IP address. So the sending server asks for that name's A record as well.
4 / 4
DNS server → sending mail server: IP address
The IP address 202.131.24.29 comes back. The sending mail server delivers the mail to this address.
1 / 4
Receiving mail server → DNS server: ask for the TXT record
The receiving mail server asks for the TXT record of naver.com, the domain in the sender address.
2 / 4
DNS server → receiving mail server: SPF list
The line that starts with v=spf1 is the SPF record. What follows ip4: is a range of IPs allowed to send mail. For example, 111.91.135.0/27 means IPs whose first 27 bits match: the 32 addresses from 111.91.135.0 to 111.91.135.31. The real list has eight such ranges.
3 / 4
Receiving mail server: check the first email
The first email came from 111.91.135.10. It is inside the listed range 111.91.135.0–31, so it passes the SPF check.
4 / 4
Receiving mail server: check the second email
The second email came from 203.0.113.50. It is not in the list, so the server suspects it is spoofing naver.com. The list ends with ~all, which tells receivers to treat anything outside it as suspicious (soft fail). So receivers accept the mail but mark it as suspicious or send it to the spam folder. Ending with -all would mean it may be rejected.
1 / 5
My PC → DNS server: ask for the NS records
My PC asks for the NS records of naver.com.
2 / 5
DNS server → my PC: list of name servers
ns1, ns2, and ns3 come back as the name servers for naver.com. There are several so that one can answer if another stops.
3 / 5
My PC → DNS server: ask for the SOA record
Now my PC asks for the summary information of the naver.com zone with an SOA record.
4 / 5
DNS server → my PC: zone summary
An SOA answer holds seven values in order. First is the primary name server, which has the original records. Next is the admin email. In the record, an email address is written like a domain name, with a dot where the @ goes. So you read webmaster.naver.com as webmaster@naver.com by turning the first dot into @. The serial number goes up every time the records change, and is often a date followed by that day's revision number.
5 / 5
SOA: the four timer values
Secondary name servers keep a copy of the primary's records and answer from it. Every refresh interval (6 hours) they check the serial number and copy the records again if it went up. If the check fails, they try again every retry interval (30 minutes). If it keeps failing past the expire time (14 days), they stop answering from their copy. The minimum TTL (Time To Live, 3 minutes) is the longest time other DNS servers remember an answer that says “no such name or record.”