The question leaves, and does almost nothing on the way out. Six stops between pressing return and getting an address.
Stop five is a room like this one. The other five stops are somebody else’s room, and that is the whole arrangement.Photograph
01Your machine
The question leaves, and does almost nothing on the way out
The resolver on your laptop is a stub. It sends the whole name to one configured server, sets a bit asking for recursion, and waits. Everything below this line happens somewhere else.
A trace on screen is the only place a query’s passivity is visible: one message out, one message back, and no record of the route it took.Photograph
02The cache
Most questions stop here, and you never learn it
The recursive resolver checks what it already holds. If the record is there and its countdown has not finished, that is your answer and no other server is contacted — which is also why a change you made an hour ago is not visible to you yet.
Two engineers reading the same bench from opposite ends. Neither of them can see what a resolver on somebody else’s network is still holding.Photograph
03The root
Asked, and it declines to answer
One of thirteen addresses replies with a referral: the servers responsible for .org, and their addresses. It has no opinion about anything inside .org and no way to find out.
One machine, lit, in a facility answering on one of thirteen addresses and holding no answers of its own.Photograph
04The registry
Another referral, one label further down
The servers for .org name the servers for the zone, and publish their addresses too. Those addresses are the glue. Without them the resolver holds a name it cannot use.
A delegation drawn by hand is the only version of it anybody can read. The zone carries the version that counts.Photograph
05Authoritative
The one machine that actually holds the record
It answers from data it was given and resolves nothing on anybody’s behalf. tinydns answered from a single prebuilt file and refused the second job outright; NSD, Knot and the PowerDNS authoritative server all take the same position now.
One rack unit. Everything the name resolves to lives on it, and it resolves nothing on anybody else’s behalf.Photograph
06Back, and stored
The countdown starts the moment you get the answer
The record arrives with a time to live, and the cache counts down. Until it reaches zero, that value is what the world sees, whatever you have since changed. The root’s own delegation records carry six days.
Cable labels are the only place a delegation is written down in the physical world. Where they disagree with the zone, the zone wins and nobody finds out for months.Photograph
Where it actually breaks
Four failures account for most real outages, and all four are visible from outside the organisation that caused them.