beginner · read-only
Domain names, DNS, URLs, hosting, CDN, and email
Learn what each layer identifies or delivers, where one layer ends, and why a DNS answer cannot prove that a website or email works.
ClueDNS knowledge path
Start with the systems and people involved, then follow the protocol evidence without collapsing distinct responsibilities into one provider.
beginner · read-only
Learn what each layer identifies or delivers, where one layer ends, and why a DNS answer cannot prove that a website or email works.
beginner · read-only
Separate the registrant, registrar, registry, DNS host, authoritative server, resolver, web host, CDN, and email provider.
beginner · read-only
Follow a cache miss through a recursive resolver, root referral, TLD referral, authoritative server, final response, and client cache.
beginner · read-only
Distinguish the server that finds and caches an answer for a client from the server that publishes data for a DNS zone.
intermediate · read-only
Understand zone boundaries, referrals, parent and child nameserver data, and the address records that break nameserver lookup dependencies.
intermediate · read-only
Understand the root zone, 13 named authorities, independent operators, distributed anycast instances, and resolver bootstrap data.
intermediate · ownership-impacting
Understand a typical gTLD registration lifecycle, the recovery windows after expiry, registrar transfers, and what RDAP data can establish.
beginner · read-only
Build a practical map of address, alias, delegation, email, policy, service-discovery, reverse-DNS, and DNSSEC record types.
intermediate · read-only
Understand how independent caches age DNS answers, how absent names are cached, and why DNS changes have no global propagation percentage.
intermediate · read-only
Understand how DNSKEY, DS, RRSIG, NSEC, and NSEC3 let validating resolvers authenticate DNS data and where a broken chain becomes bogus.
intermediate · availability-impacting
Plan, approve, execute, verify, and roll back DNS changes with explicit owners, evidence, stop conditions, and application-layer checks.
Provider-specific · verified 2026-07-28
Apply the neutral migration and DNSSEC model to Cloudflare's current full-setup workflow.