Home/Labs/DNS Hierarchy & Anycast
All 280 Labs
INTERACTIVE LAB🌳

DNS Resolution & Anycast Routing Lab (Interactive)

Step through Root → TLD → Authoritative hops and compare Anycast resolvers, cache tiers, and record types. Iterative DNS resolution with per-hop latency accounting: cold recursion versus resolver/browser cache hits and nearby Anycast versus remote ISP resolvers.

DNS Resolution & Anycast Latency Lab

Walk the Root → TLD → Authoritative hierarchy and compare cold recursion against cached answers and nearby Anycast resolvers.

OS Stub Resolver / /etc/hosts

Check local caches for api.stripe.com

0.5 ms

Recursive Resolver 1.1.1.1 (Anycast PoP)

Waiting in pipeline

PENDING

Root Nameserver (.)

Waiting in pipeline

PENDING

TLD Nameserver (.com)

Waiting in pipeline

PENDING

Authoritative NS (AWS Route 53)

Waiting in pipeline

PENDING

Recursive Resolver → Client

Waiting in pipeline

PENDING
Hop 1 / 6Cumulative: 0.5 ms / 21.0 ms

OS Stub Resolver / /etc/hosts

The OS checks its resolver cache and the hosts file before any network traffic.

Wire packet (UDP port 53)
Query: Check local caches for api.stripe.com
Answer: MISS — forward to recursive resolver
Hop RTT: 0.5 ms

How It Works Under the Hood

DNS resolution cascades through browser cache, OS cache, and the recursive resolver before touching the hierarchy of Root nameservers (13 logical clusters, Anycast-replicated), TLD servers like Verisign for .com, and the zone-authoritative nameservers holding the real A records with their TTLs. A fully cold lookup costs 50–200ms, but aggressive resolver caching means most lookups finish under 10ms. Anycast announces one IP from hundreds of cities so BGP delivers you to the nearest PoP, while GeoDNS intentionally returns different IPs per region — the foundation of multi-region active-active routing.

Core Architectural Principles

  • Four-stage recursion: Recursive Resolver → Root NS → TLD NS → Authoritative NS, each with referral latency.
  • TTL governs caching duration and failover speed — lower it to 60s before migrations, raise after.
  • CNAMEs cannot sit at the zone apex; ALIAS/ANAME records can point naked domains at an ALB.
Interview Round Script

In multi-region designs, explain GeoDNS or Route53 latency-based routing returns region-specific IPs, and mention the TTL strategy: drop to 60 seconds before a planned traffic migration so failback is fast, then raise to 3600 for caching efficiency. Knowing A vs AAAA vs CNAME vs ALIAS boundaries is a frequent junior-versus-senior separator.

Key Trade-Offs

High TTLs reduce DNS query load and latency but slow failover propagation; very low TTLs enable fast rerouting at the cost of query overhead.

Related Curriculum Chapter

DNS Resolution & Anycast Routing

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs