Step 1 · beginner · read-only
Domain names, DNS, URLs, hosting, CDN, and email
Learn what each layer identifies or delivers, where one layer ends, and why a DNS answer cannot prove that a website or email works.
New to DNS? Follow the numbered lessons in order. If you already know the basics, start at the task or concept you need.
Guided path
Build the control-plane model first, then move through resolution, delegation, registration, records, caching, DNSSEC, and safe changes.
Step 1 · beginner · read-only
Learn what each layer identifies or delivers, where one layer ends, and why a DNS answer cannot prove that a website or email works.
Step 2 · beginner · read-only
Separate the registrant, registrar, registry, DNS host, authoritative server, resolver, web host, CDN, and email provider.
Step 3 · beginner · read-only
Follow a cache miss through a recursive resolver, root referral, TLD referral, authoritative server, final response, and client cache.
Step 4 · beginner · read-only
Distinguish the server that finds and caches an answer for a client from the server that publishes data for a DNS zone.
Step 5 · intermediate · read-only
Use dig, delv, or Resolve-DnsName to separate recursive observations, referrals, authoritative answers, DNSSEC validation, and transport behavior.
Step 6 · intermediate · read-only
Understand zone boundaries, referrals, parent and child nameserver data, and the address records that break nameserver lookup dependencies.
Step 7 · intermediate · read-only
Understand the root zone, 13 named authorities, independent operators, distributed anycast instances, and resolver bootstrap data.
Step 8 · intermediate · ownership-impacting
Understand a typical gTLD registration lifecycle, the recovery windows after expiry, registrar transfers, and what RDAP data can establish.
Step 9 · beginner · read-only
Build a practical map of address, alias, delegation, email, policy, service-discovery, reverse-DNS, and DNSSEC record types.
Step 10 · intermediate · read-only
Understand how independent caches age DNS answers, how absent names are cached, and why DNS changes have no global propagation percentage.
Step 11 · intermediate · read-only
Understand how DNSKEY, DS, RRSIG, NSEC, and NSEC3 let validating resolvers authenticate DNS data and where a broken chain becomes bogus.
Step 12 · intermediate · availability-impacting
Plan, approve, execute, verify, and roll back DNS changes with explicit owners, evidence, stop conditions, and application-layer checks.
Practice safely
Explore synthetic DNS timing and change scenarios without querying or modifying a live domain.
Interactive · optional local storage
Build a locally stored draft with explicit owners, preflight evidence, stop conditions, verification, and rollback.
Interactive · browser-local
Explain the shared fields and type-specific RDATA in one locally entered presentation-format record.
Interactive · browser-local
Compare cold-cache, answer-cache, and delegation-cache paths for one fixed synthetic query.
Interactive · browser-local
Place a change and an observation on one resolver's positive or negative cache timeline.
Apply the model
Use dated provider instructions only after the portable DNS model is clear.
Provider-specific · verified 2026-07-29
Apply the neutral migration and DNSSEC model to Cloudflare's current full-setup workflow.