PrepZone Logo
PrepZone

DNS Fundamentals

How a domain name becomes an IP address and why DNS matters at every layer of scale.

How DNS resolution works

When a browser requests api.streamhub.com, it does not know the server's IP. A multi-step lookup resolves the name.

DNS lookup path (Route 53)

querydelegationaliasCLIENT
Browser / appapi.streamhub.com
NETWORK
Route 53 Resolv…recursive lookup
NETWORK
Hosted ZoneA/AAAA alias
NETWORK
ALB / CloudFronttarget IP
Every request starts here — api.streamhub.com resolves to ALB or CloudFront.

StreamHub production architecture (AWS)

HTTPSstaticmissAPICLIENT
Mobile / WebStreamHub cli…
NETWORK
Route 53GeoDNS routing
NETWORK
CloudFrontCDN + WAF edge
NETWORK
AWS ALBTLS terminati…
NETWORK
API GatewayJWT · rate li…
STORAGE
Amazon S3media origin
COMPUTE
Amazon EKSAPI · auth · …
DATABASE
ElastiCachesessions · ho…
DATABASE
RDS Postgresprimary + rep…
INTEGRATION
Amazon MSKdomain events
ANALYTICS
OpenSearchstream discov…
OPS
CloudWatchmetrics · X-R…
End-to-end path from user to data — reference this when placing any new service.

Resolution chain

  1. Browser cache — recent lookups cached for TTL seconds.
  2. OS resolver cache — local stub resolver.
  3. Recursive resolver — ISP DNS or public resolver (8.8.8.8, 1.1.1.1).
  4. Root → TLD → authoritative — delegation until the domain's nameserver answers.
  5. A/AAAA record — IPv4 or IPv6 address returned to the client.
Java
# Trace a lookup (simplified)
dig +trace api.streamhub.com A

# Check TTL — how long clients cache this answer
dig api.streamhub.com | grep -E 'ANSWER|IN A'

DNS record types you need

RecordPurposeExample
A / AAAAHostname → IPapi.streamhub.com → 52.12.34.56
CNAMEAlias to another namewww → streamhub.com
MXMail servermail.streamhub.com
TXTVerification, SPF, DKIMv=spf1 include:...
NSAuthoritative nameserverns1.cloudprovider.com
SRVService location_https._tcp service discovery
  • A / AAAA

    PurposeHostname → IP
    Exampleapi.streamhub.com → 52.12.34.56
  • CNAME

    PurposeAlias to another name
    Examplewww → streamhub.com
  • MX

    PurposeMail server
    Examplemail.streamhub.com
  • TXT

    PurposeVerification, SPF, DKIM
    Examplev=spf1 include:...
  • NS

    PurposeAuthoritative nameserver
    Examplens1.cloudprovider.com
  • SRV

    PurposeService location
    Example_https._tcp service discovery

For system design interviews, A/AAAA, CNAME, and TTL matter most.

TTL and caching trade-offs

TTL (time to live) controls how long resolvers cache a record.

AspectLow TTL (60s)High TTL (3600s)
Failover speedFast — clients pick up new IP quicklySlow — stale IPs during migration
DNS loadMore queries to authoritative NSFewer queries, lower cost
Use caseBlue-green deploys, DR drillsStable CDN CNAMEs
  • Failover speed

    Low TTL (60s)Fast — clients pick up new IP quickly
    High TTL (3600s)Slow — stale IPs during migration
  • DNS load

    Low TTL (60s)More queries to authoritative NS
    High TTL (3600s)Fewer queries, lower cost
  • Use case

    Low TTL (60s)Blue-green deploys, DR drills
    High TTL (3600s)Stable CDN CNAMEs

StreamHub uses 60-second TTL on API endpoints during migrations and 300 seconds in steady state.

DNS in scaled architectures

DNS roles at scale

  • Load balancing — multiple A records (round-robin DNS) or CNAME to an LB hostname.
  • Geographic routing — Route 53 latency-based or geolocation policies send users to the nearest region.
  • CDN — CNAME cdn.streamhub.com → d111111abcdef8.cloudfront.net.
  • Service discovery — internal DNS (CoreDNS in Kubernetes) maps streamhub-api.default.svc.cluster.local.
Java
# Example Route 53 weighted routing during canary
api.streamhub.com:
  - type: A
    alias: lb-us-east-1
    weight: 90
  - type: A
    alias: lb-us-east-1-canary
    weight: 10

DNS as a failure point

DNS outages take down services that are otherwise healthy. Mitigations:

  • Use managed DNS with anycast (multiple global PoPs).
  • Keep TTLs low enough for failover but not so low that you DDoS yourself.
  • Monitor resolution time and NXDOMAIN rates.
  • Have a runbook for nameserver migration (pre-lower TTL 24h before change).
Java
# Health check from multiple regions
curl -w '%{time_namelookup}\n' -o /dev/null -s https://api.streamhub.com/health

Internal vs external DNS

External DNS faces the public internet. Internal DNS resolves service names inside a VPC or Kubernetes cluster — critical for microservice-to-microservice calls without hard-coded IPs.

Java
External:  api.streamhub.com     → public ALB
Internal:  video-service.prod     → 10.0.4.22 (pod IP, short TTL)

Quick recall

Everything you need if you only revisit this box.

  • DNS maps hostnames to IPs through recursive and authoritative resolvers.
  • A/AAAA for IPs, CNAME for aliases; TTL balances failover speed vs query load.
  • Low TTL for migrations; higher TTL for stable CDN endpoints.
  • DNS enables geo-routing, CDN CNAMEs, and internal service discovery.
  • DNS failure makes healthy servers unreachable — use managed anycast DNS.
  • Always include DNS in end-to-end traffic diagrams.

Test yourself

Answer these before moving on — recall is what makes it stick.