
DNS, short for Domain Name System, is what turns a domain name into the IP address of the server a website sits on. Computers find each other by numbers, while people remember names. Every device on the internet has an IP address, a string of numbers that works like a phone number, and DNS works like the internet's phone book: you give it the name in the URL, and it gives your computer the number it needs.
When you type an address such as yourbakery.co.uk into your browser, DNS servers look up the matching number in the background, and your browser then loads the site. It usually happens so quickly that you never notice it.
What is a DNS server?
A DNS server, also called a domain name server or domain server, is a computer that answers questions about domain names, mostly which IP address belongs to the name you type into your browser. Every lookup involves two kinds: a DNS resolver that asks the questions on your behalf, and name servers that hold the answers. In practice you deal with the resolver that handles your own lookups, usually your internet provider's, and the name servers where your own domain's DNS records are kept.
How does DNS work?
DNS works by passing your request along a chain of DNS servers: the DNS resolver, a root name server, a TLD name server and the authoritative name server for the domain. The TLD name server is the one for the top-level domain (TLD), the last part of the address, such as .uk. Say you type yourbakery.co.uk into your browser for the first time. Your device hands the request to the DNS resolver, and the lookup begins.
DNS resolver
The DNS resolver, also called a recursive resolver, takes your request. It's usually run by your internet provider, although you can choose a public one instead. If it has looked up the address recently, it answers straight from its cache, where it keeps the answers it has had lately. If not, it asks the other servers one by one until it has the answer, then passes the IP address back to your browser.
Root name server
Root name servers sit at the top of DNS, which makes one of them the resolver's first stop. They don't know where yourbakery.co.uk is, but they know which server handles each top-level domain, so they send the resolver on to the right one. There are 13 root name servers, labelled A to M and run by 12 independent organisations. Each letter stands for a group of machines rather than a single computer, so together they are made up of hundreds of servers spread across many countries.
TLD name server
Next, the resolver asks the TLD name server, the name server for the top-level domain. For yourbakery.co.uk that's the server for .uk domains, since .uk is the UK's country code top-level domain and .co.uk is one of the domain extensions under it. The TLD name server doesn't hold the website's address either, but it knows which name servers are in charge of yourbakery.co.uk and points the resolver to them.
Authoritative name server
The last stop is the authoritative name server for yourbakery.co.uk. It holds the domain's own DNS records, so it gives the final answer: the IP address of the server the website sits on. For your own domain, that's a name server of whichever provider manages its DNS, whether that's us or another host. The resolver passes the address to your browser, and the website loads.
Why DNS changes take time to show
Looking up every address from scratch each time would be slow, so answers are kept for a while. Your computer and the resolver both store, or cache, the addresses they've looked up recently, which is why a site you visit often opens straight away. How long they may keep an answer depends on the record's time to live (TTL), which you choose as the domain holder. Our name servers use a default TTL of one hour, and you can set it anywhere from 10 minutes to 24 hours.
A change to your DNS records takes a while to show up for the same reason. A resolver that cached the old answer keeps using it until its TTL runs out, so some visitors may still see your old website for a while after you've pointed your domain somewhere new. If you're planning a move, lower the TTL to 10 minutes at least one full TTL before you change the records: a day ahead if it's set to 24 hours, or an hour ahead at our default. That way, resolvers have picked up the shorter TTL by the time you change the records.
DNS records and your domain's DNS settings
Your domain's DNS records are the entries on its authoritative name server that tell the internet where to send visitors and email. Each type of record has its own job:
- A record: points your domain to the IPv4 address of the server your website is on, IPv4 being the original format of IP address.
- AAAA record: does the same for an IPv6 address, the newer and longer format.
- CNAME record: makes one name an alias of another, for example to point a subdomain such as
shop.yourbakery.co.ukto a service hosted elsewhere. - MX record: tells other mail servers where to deliver email for your domain.
- TXT record: holds text that other services read, such as a domain verification code or the SPF, DKIM and DMARC settings that help other mail servers check that email from your domain really comes from you.
- NS record: names the name servers that are in charge of your domain.
You change these records wherever your domain's name servers point, which isn't always where you registered the domain. If you have a web hosting plan with us, your domain uses our name servers by default, ns01.one.com and ns02.one.com. To see which name servers it uses now, check the domain's settings where you registered it. If you registered it with us, you'll find them in our control panel. If your domain uses another host's name servers, you manage its DNS settings with that host, even if we registered the domain for you. If it uses our name servers, you manage your DNS settings in our control panel, where you can add records such as A, CNAME, MX and TXT yourself.
Register your domain with us and manage its DNS records yourself in our control panel.
Search domainsWhat is my DNS server?
Your DNS server is the resolver your device uses, and your internet provider usually sets it automatically when you connect. To see which one you're using, open the test site Browserleaks and choose its DNS Leak Test, which lists the DNS servers your browser sends its lookups to.
Your provider's resolver works fine in most cases, but you can use a public DNS service instead, such as Google Public DNS. To switch, you enter the public service's IP addresses as the DNS servers in the network settings of your device or operating system: Google's guide to using Google Public DNS lists its addresses with the steps for each system. From then on your device sends all its lookups to that service rather than to your provider. If you hadn't set your own DNS servers before, you switch back by deleting the addresses you added in those same settings.
If websites suddenly stop loading with a DNS not responding error, try restarting your router or opening the site on another device first.
How to keep your domain's DNS safe
Because every visit to your website starts with a DNS lookup, attackers target DNS. In DNS cache poisoning, also called DNS spoofing, an attacker slips false records into a resolver's cache, so it sends visitors to a fake website instead of the real one, where they may be tricked into giving away passwords or card details. In a DNS amplification attack, a kind of reflection attack, an attacker sends lookup requests to open DNS servers with the victim's address as the return address, and the much larger replies flood the victim's systems.
Against cache poisoning, you can use DNSSEC for your domain. It adds digital signatures to your domain's DNS records, so resolvers can check that an answer really comes from your domain and hasn't been tampered with on the way. If your domain uses our name servers, DNSSEC is on by default. Amplification attacks use DNS servers to flood someone else's systems, so stopping them is up to whoever runs those servers rather than to you as a domain holder. Domain Lock, an add-on you can buy for a domain registered with us, guards against a different risk: it stops anyone from transferring your domain to another registrar without your permission.
Put your own domain's DNS to work
Everything you do with a domain, from opening a website to receiving email on it, comes down to a few records that point it to the right servers. If you don't have one yet, register your own domain with us, then point its A record to your website and, if your email is hosted elsewhere, its MX record to your email provider. On our name servers, the MX record points to our mail servers by default.
Recommended reading
Domain2 Oct 2026What is a .si domain?
Domain9 Sept 2026How to choose a domain name - tips & tricks
With the abundance of websites on the internet, choosing a domain name can be overwhelming. Continue reading for some tips & tricks on how to pick yours.
Domain5 Aug 2026Domain names and SEO: what you should know
Start your website off on the right foot by choosing a domain name that will boost your website’s visibility on search engines.