Learn DNS from ownership to answer

New to DNS? Follow the numbered lessons in order. If you already know the basics, start at the task or concept you need.

Guided path

Core lessons

Build the control-plane model first, then move through resolution, delegation, registration, records, caching, DNSSEC, and safe changes.

Step 2 · beginner · read-only

Who controls each part of a domain

Separate the registrant, registrar, registry, DNS host, authoritative server, resolver, web host, CDN, and email provider.

Step 4 · beginner · read-only

Recursive versus authoritative DNS

Distinguish the server that finds and caches an answer for a client from the server that publishes data for a DNS zone.

Step 5 · intermediate · read-only

DNS diagnostic commands

Use dig, delv, or Resolve-DnsName to separate recursive observations, referrals, authoritative answers, DNSSEC validation, and transport behavior.

Step 6 · intermediate · read-only

DNS zones, delegation, NS, and glue

Understand zone boundaries, referrals, parent and child nameserver data, and the address records that break nameserver lookup dependencies.

Step 8 · intermediate · ownership-impacting

Domain lifecycle, expiry, transfer, and RDAP

Understand a typical gTLD registration lifecycle, the recovery windows after expiry, registrar transfers, and what RDAP data can establish.

Step 9 · beginner · read-only

DNS record types organized by purpose

Build a practical map of address, alias, delegation, email, policy, service-discovery, reverse-DNS, and DNSSEC record types.

Step 10 · intermediate · read-only

DNS TTL, caching, and propagation

Understand how independent caches age DNS answers, how absent names are cached, and why DNS changes have no global propagation percentage.

Step 11 · intermediate · read-only

DNSSEC and the chain of trust

Understand how DNSKEY, DS, RRSIG, NSEC, and NSEC3 let validating resolvers authenticate DNS data and where a broken chain becomes bogus.

Step 12 · intermediate · availability-impacting

Safe DNS-change checklist

Plan, approve, execute, verify, and roll back DNS changes with explicit owners, evidence, stop conditions, and application-layer checks.

Practice safely

Browser-local labs

Explore synthetic DNS timing and change scenarios without querying or modifying a live domain.

Interactive · optional local storage

Safe DNS-change planner

Build a locally stored draft with explicit owners, preflight evidence, stop conditions, verification, and rollback.

Interactive · browser-local

DNS record anatomy

Explain the shared fields and type-specific RDATA in one locally entered presentation-format record.

Interactive · browser-local

Root-to-answer path

Compare cold-cache, answer-cache, and delegation-cache paths for one fixed synthetic query.

Interactive · browser-local

TTL and cache timeline

Place a change and an observation on one resolver's positive or negative cache timeline.

Apply the model

Provider-specific guidance

Use dated provider instructions only after the portable DNS model is clear.

Provider-specific · verified 2026-07-29

Cloudflare nameserver onboarding

Apply the neutral migration and DNSSEC model to Cloudflare's current full-setup workflow.