How Domain Name Servers Work

DNS is Constantly Evolving

Now you know more about domain name servers, how DNS maps domain names to IP addresses, and how to choose your domain name and configure it to work within the distributed system of DNS servers around the world. Furthermore, you're in the zone with zone files and registered for success with domain name servers.

You should understand that DNS is not a static concept. In late 2018, ICANN finally rolled out new security features for DNS. In short, those changes affected the cryptographic keys used in the Domain Name System Security Extensions (DNSSEC) protocol, known by techies as the root zone key signing key (KSK). The security improvements were necessary, says ICANN, because of the way networks are rapidly changing and expanding, in part due to the Internet of Things, which brings millions of new interconnected devices into the internet's fold [source: Cooney].

Those safety measures are incredibly important because criminal-minded hackers often try to tap into the DNS system to steal personal information or simply wreak havoc, for example, in attacks like DNS hijacking. That means defense-minded computer users and IT professionals alike must stay up to date on preventative measures to prevent DNS poisoning attacks and denial-of-service attacks, among others [sources: Greenberg, SecurityTrails].

But there's an even bigger picture at stake with the status of DNS. It's often possible for tech gurus and powerful companies (or oppressive political regimes) to track traffic DNS traffic. In the wrong hands, that kind of data could be used for all sorts of nefarious ventures without any sort of regulatory oversight. In 2018, the internet Engineering Task Force accepted a new DNS-over-HTTPS as a standard – essentially an encryption concept meant to offer better privacy for everyone who uses the internet, no matter their purposes, making it much more difficult for manipulative or evil-minded digital empires to follow you around online [sources: Chirgwin, Morgenroth].

Like all things Internet, though, the new DNS-over-HTTPS paradigm is anything but a settled matter and subject to all sorts of potential adjustments and alterations. In other words, like the internet itself, the phone book that is DNS will keep evolving at an ever-faster pace – and it's increasingly important to maintain and protect these resources to keep our networks working like they should.

