Internet Infrastructure: DNS, WHOIS, and Domain Systems
Understand the core infrastructure of the internet including DNS hierarchy, WHOIS databases, Regional Internet Registries, and how domain names are managed globally.
How the Internet's Naming System Works
Every time you visit a website, a complex global infrastructure translates human-readable domain names into machine-readable IP addresses. Understanding this infrastructure is essential for network security, reconnaissance, and troubleshooting.
The DNS Hierarchy
Root Servers
The DNS hierarchy starts at the root, managed by 13 logical root server clusters (A through M) operated by organizations like ICANN, NASA, and the Internet Systems Consortium.
# Query root servers directly
dig . NS +short
# Trace resolution from root
dig example.com +trace | head -20
Top-Level Domains (TLDs)
TLDs are managed by registries under ICANN oversight:
Second-Level Domains
Individual domains like "example" in "example.com" are registered through accredited registrars.
WHOIS Infrastructure
ICANN's Role
ICANN (Internet Corporation for Assigned Names and Numbers) coordinates the global DNS system:
Regional Internet Registries (RIRs)
Five RIRs manage IP address allocation globally:
| RIR | Region | WHOIS Server |
|-----|--------|--------------|
| ARIN | North America | whois.arin.net |
| RIPE NCC | Europe, Middle East, Central Asia | whois.ripe.net |
| APNIC | Asia Pacific | whois.apnic.net |
| LACNIC | Latin America and Caribbean | whois.lacnic.net |
| AFRINIC | Africa | whois.afrinic.net |
# Query specific RIR WHOIS servers
whois -h whois.arin.net "n 8.8.8.8"
whois -h whois.ripe.net 8.8.8.8
WHOIS vs RDAP
The Registration Data Access Protocol (RDAP) is replacing WHOIS:
Domain Registration Process
How Domains Get Registered
WHOIS Record Creation
When a domain is registered, the WHOIS record includes:
DNS Record Types Explained
Core Records
| Record | Purpose | Example |
|--------|---------|---------|
| A | Maps domain to IPv4 | example.com → 93.184.216.34 |
| AAAA | Maps domain to IPv6 | example.com → 2606:2800:220:1::248 |
| CNAME | Creates alias | www.example.com → example.com |
| MX | Directs email | example.com → mail.example.com |
| NS | Delegates DNS | example.com → ns1.example.com |
| SOA | Zone metadata | Start of Authority data |
Extended Records
| Record | Purpose |
|--------|---------|
| TXT | Arbitrary text (SPF, DKIM, verification) |
| SRV | Service location |
| PTR | Reverse DNS lookup |
| CAA | Certificate Authority Authorization |
| DNSKEY | DNSSEC public key |
| DS | Delegation Signer |
DNS Resolution Process
How a Domain Resolves
1. Browser checks local cache
2. OS checks resolver cache
3. Resolver queries root server → gets TLD server
4. Resolver queries TLD server → gets authoritative NS
5. Resolver queries authoritative NS → gets IP address
6. Browser connects to IP address
Tracing DNS Resolution
# Full trace from root
dig example.com +trace
# Query each level manually
dig . NS +short # Root servers
dig com. NS +short # TLD servers
dig example.com NS +short # Authoritative servers
dig @ns1.example.com example.com # Final resolution
Infrastructure Security Considerations
DNS Security
###防护措施
# Enable DNSSEC
# Configure in your registrar's control panel
# Restrict zone transfers
# Only allow authorized secondary DNS servers
# Use DNS over HTTPS (DoH) or DNS over TLS (DoT)
# Encrypt DNS queries to prevent interception
# Monitor DNS changes
# Set up alerts for unauthorized modifications
Network Reconnaissance Using Infrastructure Knowledge
IP Address Investigation
# Identify the network owner
whois $(dig target.com A +short) | grep -E "NetRange|OrgName"
# Find related IP ranges
whois $(dig target.com A +short) | grep "CIDR"
# Check for BGP relationships
whois -h whois.radb.net -- "-i origin AS15169"
ASN Discovery
# Find ASN for an IP
whois -h whois.cymru.com " -v 8.8.8.8"
# Get all IP ranges for an ASN
whois -h whois.radb.net -- "-i origin AS15169" | grep "^route:"
Frequently Asked Questions
How does DNS caching work?
DNS resolvers cache responses for a period defined by the TTL (Time to Live) value in the DNS record. Lower TTLs mean faster updates but more queries.
What is the difference between authoritative and recursive DNS?
Authoritative DNS servers hold the actual DNS records for a domain. Recursive DNS servers (like 8.8.8.8) query authoritative servers on behalf of clients and cache the results.
How do I check if a domain uses DNSSEC?
Use dig example.com +dnssec or check with online validators like DNSViz or Verisign's DNSSEC debugger.
Why are there 13 root server clusters?
This is a historical limitation based on the original DNS packet size (512 bytes). Modern DNS uses anycast to distribute root servers globally while maintaining 13 logical addresses.
How often does WHOIS data update?
WHOIS data updates in real-time when a domain is modified. However, cached WHOIS responses from third-party services may be stale by hours or days.