Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

DNS finds a name through delegation: each name server handles the part of the namespace for which it has authoritative information and can refer a resolver to the next authority. The root points toward a top-level domain (TLD), the TLD points toward a domain’s authoritative servers, and those servers provide the requested record. No single server needs every domain’s final data.

Why DNS is distributed

The Domain Name System (DNS) maps names to records used by internet services. The namespace is divided into zones, and authority for those zones is distributed among name servers. RFC 1034 describes the principle directly: “Name servers know the parts of the domain tree for which they have complete information; a name server is said to be an AUTHORITY for these parts of the name space.” RFC 1034 also explains that zone information is served by name servers that can provide redundant service.

This division means servers do not need a complete, constantly updated map of every name and its final address. Instead, DNS uses referrals to guide a query toward the authority responsible for the requested information.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How a DNS lookup reaches the right server

When an application needs a record for a name, it typically asks a recursive resolver. The resolver pursues the answer on the application’s behalf. If it cannot use a cached answer or referral, it can start at the root and follow referrals down the hierarchy:

  1. Ask a root server. The root provides a referral to the name servers responsible for the relevant TLD, such as the authority for .com.
  2. Ask a TLD name server. The TLD authority provides a referral to the authoritative name server for the domain.
  3. Ask the domain’s authoritative server. That server returns the requested record from the zone data for which it is responsible.
  4. Return the result. The recursive resolver sends the answer back to the application and may cache information so it can be reused while valid.

ICANN’s SAC 005 describes the referral-based process. Caching can reduce repeated traversal: a resolver with usable cached information does not necessarily contact a root server for every query.

What each level knows

Each level supplies the next piece of the route rather than holding every final answer. The root’s role is to direct resolvers to TLD authorities; it does not need a complete list of all hosts and their addresses.

Server role What it does in a lookup
Recursive resolver Pursues an answer for a client, follows referrals as needed, and can cache learned information.
Root server Refers the resolver to the authority for the relevant TLD.
TLD name server Refers the resolver to the authoritative server for a domain under that TLD.
Domain authoritative server Answers from the zone data for which it is responsible.

The distinction between resolver and authority matters: a resolver works toward an answer for a client, while an authoritative server answers from its own zone data. RFC 1034 and RFC 1035 describe this distributed organization and the resolver’s use of name servers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why there are 13 named DNS root servers

The phrase “13 root servers” refers to 13 named root-server identities, not 13 individual physical machines. The RSSAC FAQ addresses this common question; the shorthand should not be mistaken for a count of the machines or deployments supporting root service. The current deployment count is not needed to understand how referrals work.

One public root, distributed authority

Distributed DNS authority does not mean the public DNS root is a collection of unrelated global roots. ICANN describes a single authoritative public root in ICP-3. That uniqueness coexists with distributed operation: authorities manage different zones, and root service is provided through the named root-server identities and their supporting deployments.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A directory analogy—and its limits

Imagine a directory whose first entry points you to the custodian for a suffix, and whose next entry points you to the custodian for a particular domain. That captures how a resolver can move from a known starting point toward the server responsible for a name without any one custodian holding all final answers.

The analogy is incomplete. DNS is a protocol and database system with resource records, zones, delegation, caching, and operational coordination—not a human directory. The important idea is the division of authority: each server needs the information for its part of the namespace and enough referral information to direct queries onward.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.