What Is a DNS Server? How Your Browser Finds a Website
A DNS server turns names like example.com into IP addresses. The different kinds — resolvers, root servers, authoritative nameservers — how a lookup works step by step, public resolvers like 1.1.1.1 and 8.8.8.8, and the DNS errors you'll actually run into.
Computers find each other on the internet by IP address — numbers like 93.184.215.14. People use names like example.com. A DNS server is what translates one into the other. DNS stands for Domain Name System: the internet's phone book. (What is a domain name?, IP addresses and ports)
There are two very different kinds
When people say "DNS server", they mean one of two things:
1. Resolvers — the ones that look things up for you
Your device asks a recursive resolver "what's the address of example.com?". The resolver does the legwork and gives you the answer. Your internet provider runs one, and there are public ones:
- 1.1.1.1 — Cloudflare
- 8.8.8.8 — Google
- 9.9.9.9 — Quad9 (blocks known malicious domains)
2. Authoritative nameservers — the ones that know the answer
Each domain has authoritative nameservers that hold its real records: which IP the website is on, where email goes, and so on. When you set up DNS at Cloudflare or your registrar, you're editing records on their authoritative nameservers. (DNS records explained)
How a lookup works
When you type blog.example.com:
- Your computer checks its own cache. If it looked this up recently, done.
- If not, it asks your resolver (say 1.1.1.1).
- The resolver asks a root server: "who handles
.com?" - The root server points to the .com servers.
- The resolver asks the .com servers: "who handles
example.com?" They point to example.com's authoritative nameservers. - The resolver asks those: "what's the address of
blog.example.com?" They answer with the IP. - The resolver caches the answer for the record's TTL (time to live) and gives it to your browser.
This usually takes milliseconds, and most lookups are answered from a cache along the way.
Why caching matters to you
Because answers are cached for their TTL, DNS changes don't show up everywhere at once. If you point your domain at a new server, some people see the old one until their resolver's cached copy expires. That's "DNS propagation". (DNS propagation explained)
Lower the TTL (say to 300 seconds) a day before a planned change to make the switch faster.
Should you change your DNS server?
Switching your computer or router from your provider's resolver to 1.1.1.1, 8.8.8.8 or 9.9.9.9 can be faster, more reliable, and in some cases more private (many support encrypted DNS). It's harmless to try. It doesn't change anything about your website's DNS — that's the authoritative side.
Checking DNS yourself
nslookup example.com # Windows, Mac, Linux
dig example.com # Mac, Linux — more detail
dig example.com @1.1.1.1 # ask a specific resolver
dig NS example.com # which nameservers are authoritative
Online tools like whatsmydns.net show what resolvers around the world currently see.
DNS errors you'll meet
- DNS_PROBE_FINISHED_NXDOMAIN — the name doesn't exist (typo, expired domain, missing record). (Fix it)
- "This site can't be reached" — often DNS, sometimes the server. (Fix it)
- Site works for you but not others (or vice versa) — caching during propagation.
The summary
- DNS turns names into IP addresses.
- Resolvers look things up for you; authoritative nameservers hold your domain's records.
- Answers are cached for their TTL, which is why changes take time.
- Use
digornslookupto see what's really happening.
EasySpawn tells you exactly which DNS records to add for your domain, then handles HTTPS automatically once they point at your server. See how it works or join the waitlist.
Related: DNS Records Explained · How to Connect a Custom Domain · What Is Cloudflare? · IPv4 vs IPv6
Keep reading
IPv4 vs IPv6: What's the Difference and Does It Matter for Your App?
IPv4 addresses look like 203.0.113.7; IPv6 addresses look like 2001:db8::1. Why the internet ran out of IPv4, what IPv6 changes, A vs AAAA DNS records, and the practical things app builders need to check — like listening on both and firewalls.
Cloudflare Tunnel Explained: Put a Local App Online Without Opening Ports
Cloudflare Tunnel connects an app on your laptop, home server or private network to the internet through Cloudflare, with no public IP or open firewall ports. Quick tunnels for testing, named tunnels with your own domain, Access for protection, and when to use it instead of a server.