Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A domain name server is a DNS server that stores or provides information for a domain or DNS zone. The term commonly refers to an authoritative name server, which supplies the definitive DNS records for a zone. A recursive resolver has a different job: it finds answers for a client by querying DNS servers or using cached records.

What does a domain name server do?

DNS servers help translate domain names into information applications need, such as the records used to locate a website. An authoritative name server holds the definitive DNS information for its zone and responds to queries about that information. AWS describes it as a server with definitive information about one part of DNS (AWS Route 53 concepts).

When a domain owner sees “nameservers” in a registrar or DNS-hosting control panel, the setting usually identifies the authoritative DNS service for the domain. For example, Cloudflare uses “nameserver” for its authoritative servers, which hold and provide a domain’s definitive records (Cloudflare DNS concepts).

Domain name server vs. recursive resolver

“DNS server” is a broad term that can describe servers with different roles. The key distinction is whether the server provides authoritative data for a zone or finds data on behalf of a client.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Role What it does Typical user
Authoritative name server Serves definitive DNS records for its zone. Domain owners configure it for their domains.
Recursive resolver Accepts client DNS requests, queries other DNS servers as needed, and returns an answer; it may use cached data. Devices and networks use it to look up domain names.

A resolver is usually the first DNS server a client contacts. It is an intermediary between the client and DNS name servers, and is also called a recursive name server because it can query a sequence of authoritative servers to find an answer (AWS Route 53 concepts; Cloudflare DNS server types).

How a DNS lookup works

For a typical lookup with no usable cached answer, the client asks a recursive resolver to find the requested DNS record. The resolver follows the DNS hierarchy and returns the result to the client:

Rank #2
Sale
DNS For Dummies
  • Used Book in Good Condition
  1. The resolver queries a root name server to find the relevant top-level domain (TLD) server.
  2. It asks the TLD server where to find the domain’s authoritative name server.
  3. It queries that authoritative server for the requested record.
  4. It sends the answer back to the client.

This is a typical path, not a requirement that every browser request contact all these servers. A resolver may already have a usable cached answer, and some records, such as aliases, can require additional lookups (Cloudflare: What is a DNS server?).

Why DNS answers can be cached

A caching resolver can keep a DNS record and reuse it instead of repeating the full lookup. The record’s time to live (TTL) determines how long a caching name server may retain it. Once the relevant cache period ends, the resolver may need to obtain a fresh answer.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is why a DNS change may not appear immediately to every user: some resolvers may still have an earlier answer in cache. The duration depends on the TTL of the relevant record and the resolver’s cache state (ICANN-hosted Introduction to the DNS; Cloudflare: What is a DNS server?).

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What DNSSEC adds

DNS by itself does not give a resolver strong assurance that an answer came from the expected source and was not altered. DNS Security Extensions (DNSSEC) add data-origin authentication and integrity protection through digital signatures on DNS data. A validating resolver can check those signatures when the relevant zones are signed and the chain of trust is configured.

DNSSEC is not automatic: network operators must enable validation at recursive resolvers, and domain owners must enable it for their authoritative zones. It authenticates DNS data; it does not encrypt DNS queries or hide the domain being requested (ICANN DNSSEC explainer).

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.