primarydns.nl
Nerd tools
primarydns.nl explains

Where does a website actually live?

The internet doesn’t know names, only numbers. Scroll along and watch DNS guide your browser from name to IP address in milliseconds.

Start the journey ↓ Skip to tools
one lookup, live~40 ms
YOU
browser
DNS
Resolver
.nl
nameserver
primarydns.nl 49.13.238.87
Chapter 1 · What is DNS?

The internet’s phonebook

Computers find each other by IP address, strings of digits like 49.13.238.87. Great for machines, hopeless for humans. DNS (the Domain Name System) translates names you can remember into numbers computers understand. Every time you type an address, that phonebook gets consulted at lightning speed.

One name can hold several numbers, by the way, that’s how you spread traffic across servers.

The phonebook
primarydns.nl49.13.238.87
sidn.nl34.111.90.63
wikipedia.org185.15.59.224
Chapter 2 · The journey of a query

Five stops in ±40 milliseconds

You type primarydns.nl and hit enter. Here’s what happens, faster than a blink.

;; total: ~40 ms, and next time: 0 ms, thanks to the cache
Chapter 3 · Record types

One name, many kinds of answers

DNS answers more questions than just "where’s the website?". Each record type has its own job.

Chapter 4 · Caching & TTL

Remembering is fine, just not forever

Every DNS answer carries a TTL (time to live): the number of seconds you may remember it. Caches, in your browser, your router, at your resolver, respect it. That’s why DNS feels instant: most questions have been asked before. Watch one expire live, right here.

resolver cache
primarydns.nl  A49.13.238.87
TTL expires in
Chapter 5 · Propagation

Why a DNS change "takes a while"

Change a record and not everyone hears about it at once. Caches around the world politely wait for their own TTL to run out before fetching the new answer. No magic, just kitchen timers going off, some sooner than others.

old answernew answer
Every resolver flips at its own moment, that’s what we call propagation.
Chapter 6 · DNSSEC

A signature under every answer

DNS is old and naturally trusting: whoever answers first, wins. DNSSEC adds digital signatures. The root signs .nl, and .nl signs primarydns.nl, a chain of trust. If one link doesn’t check out, the answer is rejected.

Forged answers get caught: the signature doesn’t match.
Playground · What if…?

Turn the knobs yourself

Cache warm or cold? TTL short or long? DNSSEC on or off? Flip the switches and instantly see what happens to your lookup.

Browser cache
TTL
DNSSEC
Chapter 7 · Take control

Pick your own resolver

By default you use your ISP’s resolver. Fine, but not mandatory. Public resolvers are often faster, block malware or promise better privacy. And switching? A matter of minutes.

Popular picks
Not sure? Quad9 is a safe default. And switching back to your ISP is always possible.
Chapter 8 · Encrypted DNS

Who’s reading along with your questions?

Classic DNS travels as readable text across the network. Anyone along the way can read it: the coffee-shop Wi-Fi, your ISP. DoT and DoH put your questions in an encrypted envelope; only you and your resolver know the contents.

Note: encryption hides what you look up, not where you browse afterwards.

Without encryption · port 53
→ readable at every stop: "primarydns.nl?"
With DoH · port 443
→ visible along the way: ●●●●●
Interlude · A bit of history

From one text file to billions of lookups

For the nerds

Tinker away

Five toys for those who want to dig deeper. All dig-style, all live.

$
FAQ

Frequently asked questions