DNS, explained with a lookup you can run on this page
Every page load starts with a question your computer asks the network: what IP address does this name belong to? DNS is the system that answers it, and it answers in plain JSON you can fetch yourself right here.
The chain of who asks whom
Your browser doesn't ask the root servers directly. It asks a recursive resolver (usually your ISP's, or a public one like 1.1.1.1). That resolver walks the tree for you: the root servers point it at the right TLD servers (.com, .org, …), which point it at the domain's authoritative nameservers, which finally answer. Each answer carries a TTL — seconds the resolver may cache it — so most lookups never leave the cache.
The live demo
Cloudflare publishes DNS over HTTPS: the exact same lookup your resolver performs, returned as JSON, with open CORS so a page can call it. Type a domain and run it — you're seeing the wire format of a real DNS answer:
<div id="doh-demo">
<input id="doh-domain" value="example.com" style="padding:6px;font-size:14px;width:220px">
<button onclick="dohLookup()" style="padding:6px 12px;font-size:14px;cursor:pointer">Look up</button>
<pre id="doh-out" style="background:#111;color:#9f9;padding:12px;overflow:auto;max-height:300px;border-radius:6px"></pre>
</div>
<script>
async function dohLookup() {
const out = document.getElementById('doh-out');
const name = document.getElementById('doh-domain').value.trim();
out.textContent = 'Querying…';
try {
const r = await fetch('https://cloudflare-dns.com/dns-query?name=' + encodeURIComponent(name) + '&type=A',
{ headers: { 'Accept': 'application/dns-json' } });
const j = await r.json();
out.textContent = JSON.stringify(j, null, 2);
} catch (e) { out.textContent = 'Lookup failed: ' + e.message; }
}
</script>
Reading the answer
An answer typically looks like this (values vary; this is the shape):
{ "Status": 0, "Answer": [ { "name": "example.com", "type": 1, "TTL": 3600, "data": "an IPv4 address" } ] }
Status: 0means NOERROR — the name exists.3means NXDOMAIN: nothing there.type: 1is an A record (IPv4).type: 28is AAAA (IPv6).type: 5is a CNAME — one name aliasing another; try looking up a big site and you'll often see a CNAME chain before the A record.TTLis how long resolvers cache this. Short TTLs (60s) let sites fail over fast; long ones (a day) trade freshness for speed.
That's the whole trick of the internet's phone book: a distributed database, read through caches, where every lookup is just a chain of referrals — and you can watch one happen live above.