Concept · 9 min read
What is DNS?
How does a name become an address, and why does that matter to security?
DNS is a global, cached, hierarchical lookup system. Most 'the site is down' and 'why does this IP appear?' investigations come back to it.
The chain
A resolver walks from the root to the TLD to the authoritative zone, caching each answer for its TTL. That cache is why a change takes time to propagate and why two machines can legitimately see different answers at the same moment.
- A / AAAA — address. CNAME — alias. MX — mail. NS — who is authoritative. TXT — free-form text used for policy records.
- SOA carries the zone serial; a stale secondary is visible there.
- PTR lives in reverse zones and answers 'what name is this address?'
Record types you will actually be asked about
bash
dig +short A example.org dig +short MX example.org dig +short TXT _dmarc.example.org dig +short -x 192.0.2.10
Security relevance
- Subdomain takeover: a dangling CNAME pointing at a service nobody claims.
- Certificate transparency logs record names, which is why passive enumeration works at all.
- DNS tunneling shows up as long labels and unusually frequent queries — visible in a capture, not in an access log.
- Cache poisoning and resolver-level filtering both change what you see, which matters when you verify a finding from a second location.
Check your understanding
Answer before expanding. If you cannot explain it in one sentence, the section above needs a re-read.
A subdomain resolves but the site 404s. Is it in use?Q1
Something is configured; whether anything is served is a separate question. Record both facts.
What makes a CNAME risky here?Q2
If the target service is unclaimed, an outsider can register that name on the third-party platform and receive your visitors. That is the takeover condition.
Where this shows up
Tools in the directory whose commands assume this knowledge.