CyberNotes
CN-001PUBLIC

How DNS Actually Works

The phonebook of the internet, and why it's a favorite target for attackers.

How DNS Actually Works

Every time you type a website name into your browser, something has to translate that name into an IP address a computer can actually connect to. That translator is DNS — the Domain Name System.

The lookup chain

Your request doesn't go straight to one all-knowing server. It hops through a chain: a recursive resolver (often run by your ISP or a public one like 1.1.1.1), then root servers, then TLD servers (for .com, .org, etc.), then the authoritative server for the specific domain.

Why attackers care

Because DNS is trusted by default, it's a popular target: DNS spoofing, cache poisoning, and DNS tunneling all abuse that trust to redirect traffic or sneak data past defenses.

Defending it

DNSSEC adds cryptographic signatures so resolvers can verify responses haven't been tampered with. Monitoring DNS query logs is also one of the highest-signal, lowest-noise things a SOC can do.

← Back to topic hub