The namespace behaves like the Zone in Tarkovsky’s movie. It is a constantly changing field. Every actor is aware only of its own role. The registrar knows the domain holders, the registry knows the registrars, the DNS providers know the name servers, the domain legal specialists know the rules.
This map of domain name resolution is the first on the domain blog. The lookup chain of name resolution is what we use every day all the time without being aware of how it truly happens. That’s why this map is the first in this series due to its fundamental importance.
Every concept map delivers an answer to one single question. Which is this: how does a domain name become an answer, and where are the trust nodes along the way? The question is also an editing rule. What adds to the answer is added to the map; what doesn’t is removed. That’s why the map doesn’t have the browser included, that’s why it doesn’t have DNSSEC, and that’s why it doesn’t have the dozen or so details that would make it more professional, but unreadable.
A domain we type in our browser is in fact a question we ask. Our question here: where can we find the content that we want to read? The answer at the end of the lookup chain is going to be one IP address that tells the browser exactly where to go for the content. The key factor is trust that has to hold up at several nodes.
Nine concepts, eight connections, six steps. This is how the question runs through the whole chain:
The domain name as a question. This question starts the whole process. That is what your machine asks the resolver.
The largest part of the job is being done by the resolver. It asks the question throughout the whole chain and in the end it gives you the answer. The resolver is typically run by your internet provider, but there are openly available public services from the major players like Google or Cloudflare.
The answer from the resolver can come from two sources. One source is its cache and if it holds the answer you will get it in an instant. The other is asking the question throughout the whole lookup chain.
When the answer is not there in the cache, the next actor who gets the question is the root server. The root server is being asked about who is running that domain extension.
Then the root server guides you towards the registry of that particular extension. The registry knows which name server is responsible for which domain name.
The last step that remains is to ask the name server. Then the name server gives the exact answer to what the IP address is.
Although not part of the lookup chain, there is another actor that has a real right to decide on the answer. This actor is the domain holder’s account at the registrar. The whole DNS zone of the domain name can be controlled here.
This whole chain has critical nodes where the answer can be changed or even stopped. Moreover, there is a trust issue with all actors. The resolver can filter out the requests and its cache can be forged. At the root server level, the extension can be deleted. At the registry the domain name can be withheld. The name server can be overloaded or it can even disappear from the network. The registrant’s account is where any of the DNS records can be rewritten.
The common characteristic of the nodes of trust is that you have no direct influence over most of them. One of the key points of this map is that the name resolution process is highly trust-based.
You can start anywhere on the map, but it is easiest to read from the top, starting at the domain name.
Download: The Path of Name Resolution — PDF, A3, v1.0
Download it, print it, project it, pass it on — with attribution. You may not redraw it, relabel it, or fold it into another diagram: the map is published under CC BY-ND 4.0. For translation, adaptation, or use inside your own material, ask me first. If you find an error in it, write to me and I will fix it in the next version.
Magyar változat: [zona.hu/a-nevfeloldas-utja/]



