Baud
All protocols

DNS

The internet's phone book: names in, addresses out, in one small datagram.

A query

Twenty-nine bytes asking for the A record of example.com. The letters are visible in the ASCII row.

DNS query · 29 bytes081624AB·CD·01·00·00·01·00·00·00·00·00·00·07·65e78x61a6Dm70p6Cl65e03·63c6Fo6Dm00·00·01·00·01·Transaction IDFlagsQuestion countAnswer countAuthority countAdditional countLabel len…Label "example"Label len…Label "com"End of na…Query typeQuery classClick a field to inspect it

Whole frame

AB CD 01 00 00 01 00 00 00 00 00 00 07 65 78 61 6D 70 6C 65 03 63 6F 6D 00 00 01 00 01: 'what is the IPv4 address of example.com?' in 29 bytes, small enough for one UDP datagram.

FieldOffsetExample valueMeaning
Transaction IDByte 0–10xABCDA random number chosen by the client and copied into the reply, so it can match answers to questions (and so an attacker has to guess it).
FlagsByte 2–30x0100 = query, recursion desiredSixteen bits of control: query or response, opcode, authoritative, truncated, recursion wanted/available, response code.
Question countByte 4–51How many questions follow. Almost always 1.
Answer countByte 6–70How many answer records follow. 0 in a query.
Authority countByte 8–90Name-server records in the authority section (unused here).
Additional countByte 10–110Extra helpful records (unused here).
Label lengthByte 127Names are stored as labels, each prefixed with its length. 'example' has 7 letters.
Label "example"Byte 13–19exampleThe ASCII letters. There are no dots on the wire: the dots of example.com are replaced by length bytes.
Label lengthByte 203Next label: 'com' has 3 letters.
Label "com"Byte 21–23comThe top-level domain.
End of nameByte 240A zero-length label ends the name (it stands for the root).
Query typeByte 25–261 = AWhat record is wanted: 1 = A (IPv4 address), 28 = AAAA (IPv6), 15 = MX (mail), 5 = CNAME, 16 = TXT, 2 = NS.
Query classByte 27–281 = IN1 = IN (the Internet). Other classes are historical.

Overview

DNS translates names people remember (example.com) into addresses machines use. A query and its answer share one binary layout: a 12-byte header, then questions, then answer records. It usually travels in a single UDP datagram on port 53.

Names are stored as length-prefixed labels (7 'example' 3 'com' 0) rather than with dots, and answer records use pointers back into the message to avoid repeating names.

Key facts

Transport
UDP/53 (TCP/53 for large replies)
Header
12 bytes
Label limit
63 bytes per label, 253 per name
Common types
A, AAAA, CNAME, MX, TXT, NS
Caching
By TTL, in resolvers and clients
Standard
RFC 1035

The response

The question comes back, followed by an answer record that points at the name instead of repeating it.

DNS response · 45 bytes0816243240AB·CD·81·80·00·01·00·01·00·00·00·00·07·65e78x61a6Dm70p6Cl65e03·63c6Fo6Dm00·00·01·00·01·C0·0C·00·01·00·01·00·00·01·2C,00·04·CB·00·71q322Transaction IDFlagsQuestion countAnswer countAuthority countAdditional countLabel len…Label "example"Label len…Label "com"End of na…Query typeQuery className (pointer)TypeClassTTLData leng…AddressClick a field to inspect it

Whole frame

The response repeats the question, then adds one answer record: 'example.com is 203.0.113.50, remember it for 300 seconds'.

FieldOffsetExample valueMeaning
Transaction IDByte 0–10xABCDA random number chosen by the client and copied into the reply, so it can match answers to questions (and so an attacker has to guess it).
FlagsByte 2–30x8180 = response, recursion available, no errorSixteen bits of control: query or response, opcode, authoritative, truncated, recursion wanted/available, response code.
Question countByte 4–51How many questions follow. Almost always 1.
Answer countByte 6–71How many answer records follow. 0 in a query.
Authority countByte 8–90Name-server records in the authority section (unused here).
Additional countByte 10–110Extra helpful records (unused here).
Label lengthByte 127Names are stored as labels, each prefixed with its length. 'example' has 7 letters.
Label "example"Byte 13–19exampleThe ASCII letters. There are no dots on the wire: the dots of example.com are replaced by length bytes.
Label lengthByte 203Next label: 'com' has 3 letters.
Label "com"Byte 21–23comThe top-level domain.
End of nameByte 240A zero-length label ends the name (it stands for the root).
Query typeByte 25–261 = AWhat record is wanted: 1 = A (IPv4 address), 28 = AAAA (IPv6), 15 = MX (mail), 5 = CNAME, 16 = TXT, 2 = NS.
Query classByte 27–281 = IN1 = IN (the Internet). Other classes are historical.
Name (pointer)Byte 29–300xC00C → example.comName compression: the two top bits 11 mean 'a pointer': the name is found at offset 0x0C (byte 12) of this message, i.e. in the question. This saves repeating example.com in every record.
TypeByte 31–321 = AThe record type of this answer: A.
ClassByte 33–341 = ININ.
TTLByte 35–38300 secondsHow many seconds caches may keep this answer. 300 s = 5 minutes. Short TTLs allow quick changes; long TTLs reduce load.
Data lengthByte 39–404Bytes of data that follow: an IPv4 address is 4.
AddressByte 41–44203.0.113.50The answer itself: the IPv4 address of example.com in this demo (a documentation address).

A lookup with caching

Who asks whom, and where the answer is remembered.

Laptop192.168.1.20Resolver192.168.1.1Name serverexample.comA? example.comUDP :53, RD=1A? example.comiterativeA 203.0.113.50TTL=300, AA=1A 203.0.113.50TTL=300, RA=1cache: emptycache: example.com203.0.113.50

Whole exchange

One question, one answer, cached for the TTL. Every name lookup on the internet is a short conversation like this, usually over UDP.

  1. 1Laptop asks the resolver

    The laptop does not search the internet itself. It asks its configured resolver (often the router or the ISP) and sets RD, 'recursion desired'.

  2. 2Resolver asks the owner

    Cache miss. In reality the resolver walks from a root server to the .com servers to example.com's own name server, three queries in a row; they are drawn here as one step.

  3. 3Authoritative answer

    The server that owns the zone answers with the record and a TTL. AA = authoritative.

  4. 4Resolver answers the laptop

    The same answer is relayed with RA set. For the next 300 seconds, anyone asking this resolver gets the cached answer instantly.

Where you meet it

  • Every web request starts with a DNS lookup
  • Email routing (MX), domain ownership proofs (TXT), service discovery (SRV)
  • DNS over HTTPS/TLS wrap the same messages in encryption

Watch out for

  • 'It's always DNS': stale caches and TTLs explain most 'I changed it but nothing happened' moments.
  • Plain DNS is unencrypted and unauthenticated; the transaction ID and port are all that stop easy spoofing (DNSSEC adds signatures).
  • Answers over 512 bytes (or 1232 with EDNS0) do not fit one datagram and fall back to TCP.

Standards

  • RFC 1035: Domain Names - Implementation and Specification

Related protocols