เชฎเซเช–เซเชฏ เชธเชพเชฎเช—เซเชฐเซ€ เชชเชฐ เชœเชพเช“
JobCannon
เชฌเชงเชพ เช•เซŒเชถเชฒเซเชฏเซ‹

DNS

The internet's address book and traffic routing system

โฌข เชŸเชฟเชฏเชฐ 2เชŸเซ‡เช•เชจเชฟเช•เชฒ
+$10k-
เชชเช—เชพเชฐ เชชเชฐ เช…เชธเชฐ
4 เชฎเชนเชฟเชจเชพ
เชถเซ€เช–เชตเชพเชจเซ‹ เชธเชฎเชฏ
เชฎเชงเซเชฏเชฎ
เชฎเซเชถเซเช•เซ‡เชฒเซ€
2
เช•เชฐเชฟเชฏเชฐ
เชเช• เชจเชœเชฐเชฎเชพเช‚

DNS translates domain names to IP addresses and is infrastructure for every internet service. Beginner: A, CNAME, MX records, dig/nslookup. Intermediate: TTL, propagation, SPF/DKIM/DMARC, ALIAS. Advanced: GeoDNS, failover, DNSSEC, split-horizon. Career: SRE/DevOps/Network Engineers (+$10โ€“20k). Learning: 3โ€“4 months. Tools: BIND9, Cloudflare, AWS Route 53, Google Cloud DNS, Azure DNS. Cloudflare era reshaped DNS management with built-in DDoS protection and edge routing.

DNS เชถเซเช‚ เช›เซ‡

DNS translates domain names to IP addresses and is fundamental infrastructure for every internet application. Beyond basic resolution, DNS powers load balancing, failover, CDN routing, email delivery (MX, SPF, DKIM, DMARC), and service discovery. Misconfigured DNS is one of the most common causes of outages and email deliverability problems. Understanding DNS is critical for web deployments and debugging connectivity issues.

๐Ÿ”ง เชŸเซ‚เชฒเซเชธ เช…เชจเซ‡ เช‡เช•เซ‹เชธเชฟเชธเซเชŸเชฎ
BIND9UnboundCloudflareAWS Route 53Google Cloud DNSAzure DNSNS1ConstellixdignslookupdrilldnsmasqAdGuard DNSNextDNSQuad9

๐Ÿ’ฐ เชชเซเชฐเชฆเซ‡เชถ เชชเซเชฐเชฎเชพเชฃเซ‡ เชชเช—เชพเชฐ

เชชเซเชฐเชฆเซ‡เชถเชœเซเชจเชฟเชฏเชฐเชฎเชงเซเชฏเชฎเชธเชฟเชจเชฟเชฏเชฐ
USA$95k$135k$185k
UKยฃ55kยฃ75kยฃ105k
EUโ‚ฌ60kโ‚ฌ80kโ‚ฌ115k
CANADAC$100kC$140kC$190k

๐ŸŽฏ DNS เชจเซ‹ เช‰เชชเชฏเซ‹เช— เช•เชฐเชคเซ€ เช•เชฐเชฟเชฏเชฐ

โš– เชธเชพเชฅเซ‡ เชธเชฐเช–เชพเชฎเชฃเซ€ เช•เชฐเซ‹

โ“ FAQ

Why is DNS called 'the cause of half our outages'?
DNS failures can cascade silently, clients cache incorrect IPs, email bounces, services timeout. TTL misconfiguration prolongs outages; propagation delays mean some users see old records. A single misconfigured NS record can break an entire domain. Always test DNS changes with dig before relying on browser cache.
What's the difference between DNS-over-HTTPS (DoH) and traditional DNS?
Traditional DNS over port 53 is unencrypted, exposing queries. DoH wraps DNS over HTTPS (port 443), encrypting queries from browsers and ISPs. Most modern browsers support DoH; it's becoming standard. Trade-off: slight latency increase, blocks some DNS-based parental controls. Cloudflare, Google, Quad9 run DoH resolvers; NextDNS offers DoH with per-client rules.
How does anycast routing work in DNS?
Anycast assigns the same IP to multiple servers globally; routers direct clients to the geographically nearest one. Cloudflare, Google DNS, and NS1 use anycast for low-latency resolution. Clients always hit the closest edge without knowing. Enables global failover and DDoS resilience at the DNS layer, critical for large services.
What is GeoDNS and why is it powerful?
GeoDNS returns different A records based on client geography, allowing you to route users to nearest servers, comply with data residency laws (EU users โ†’ EU servers), or A/B test by region. Cloudflare, AWS Route 53, and NS1 all support it. Pro tip: combine with health checks for automatic failover to backup region if primary is down.
How do DNS records work in Kubernetes (ExternalDNS)?
ExternalDNS automatically creates DNS A/CNAME records from Kubernetes Ingress or Service annotations, syncing with AWS Route 53, Google Cloud DNS, or Azure DNS. When you deploy `kind: Ingress` with annotation `external-dns.alpha.kubernetes.io/hostname`, ExternalDNS registers the domain automatically. Eliminates manual DNS management in K8s environments.
SPF, DKIM, DMARC, why all three?
SPF (TXT record, IP whitelist) prevents spoofing but is easy to bypass. DKIM (public key in TXT) cryptographically signs emails. DMARC (TXT policy) ties them together: 'if DKIM+SPF pass, deliver; else quarantine/reject'. All three required for deliverability to Gmail, Office 365. Missing any one causes mail to land in spam. Always publish all three.
CNAME vs ALIAS, when do I use each?
CNAME points a subdomain to another domain (e.g., www โ†’ example.com). You CANNOT use CNAME on the zone apex (example.com). AWS, Cloudflare, and others provide ALIAS (proprietary): a zone-apex-safe pointer. Use CNAME for subdomains, ALIAS (or A record) for the root. If DNS provider doesn't support ALIAS, use A record with IP and accept manual updates.

เช–เชพเชคเชฐเซ€ เชจเชฅเซ€ เช•เซ‡ เช† เช•เซŒเชถเชฒเซเชฏ เชคเชฎเชพเชฐเชพ เชฎเชพเชŸเซ‡ เช›เซ‡?

เช•เชฐเชฟเชฏเชฐ เชฎเซ‡เชš เชŸเซ‡เชธเซเชŸ เช†เชชเซ‹ โ€” เช…เชฎเซ‡ เชฏเซ‹เช—เซเชฏ เชŸเซเชฐเซ‡เช•เซเชธ เชธเซ‚เชšเชตเซ€เชถเซเช‚.

เชฎเชพเชฐเชพ เชถเซเชฐเซ‡เชทเซเช -เชซเชฟเชŸ เช•เซŒเชถเชฒเซเชฏเซ‹ เชถเซ‹เชงเซ‹ โ†’

เชคเชฎเชพเชฐเซ‹ เช†เชฆเชฐเซเชถ เช•เชฐเชฟเชฏเชฐ เชชเชพเชฅ เชถเซ‹เชงเซ‹

2,521 เช•เชพเชฐเช•เชฟเชฐเซเชฆเซ€เช“เชฎเชพเช‚ เช•เซŒเชถเชฒเซเชฏ-เช†เชงเชพเชฐเชฟเชค เชฎเซ‡เชšเชฟเช‚เช—. เชฎเชซเชค.

เช•เชฐเชฟเชฏเชฐ เชฎเซ‡เชš เชŸเซ‡เชธเซเชŸ เช†เชชเซ‹ โ€” เชฎเชซเชค โ†’