3 ms·
The trailing dot (.) at the end of the domain name denotes the root nameservers. There are 13 such servers in the world. $ dig ns . ; <<>> DiG 9.8.1-P1 <<>> n
by dukekarthik 14y ago
The trailing dot (.) at the end of the domain name denotes the root nameservers. There are 13 such servers in the world.
$ dig ns .
; <<>> DiG 9.8.1-P1 <<>> ns .
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 38974
;; flags: qr rd ra; QUERY: 1, ANSWER: 13, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;. IN NS
;; ANSWER SECTION:
. 21088 IN NS a.root-servers.net.
. 21088 IN NS b.root-servers.net.
. 21088 IN NS c.root-servers.net.
. 21088 IN NS d.root-servers.net.
. 21088 IN NS e.root-servers.net.
. 21088 IN NS f.root-servers.net.
. 21088 IN NS g.root-servers.net.
. 21088 IN NS h.root-servers.net.
. 21088 IN NS i.root-servers.net.
. 21088 IN NS j.root-servers.net.
. 21088 IN NS k.root-servers.net.
. 21088 IN NS l.root-servers.net.
. 21088 IN NS m.root-servers.net.
;; Query time: 51 msec
;; SERVER: 127.0.1.1#53(127.0.1.1)
;; WHEN: Sat Mar 16 19:32:57 2013
;; MSG SIZE rcvd: 228
This is very helpful in DNS propagation and pointing the appropriate authoritative zone for all the TLDs.
- 16s 14y agoEvery "web developer" should read the first three chapters of the Cricket book. The profound ignorance (that many web developers have) of DNS is inexcusable: http://www.amazon.com/DNS-BIND-5th-Cricket-Liu/dp/0596100574 http://www.amazon.com/DNS-BIND-5th-Cricket-Liu/dp/0596100574
- jameshart 14y agoThe . doesn't indicate the root nameservers at all - it indicates that the DNS name to be resolved is an absolute name, not a relative name. All nameservers - root or otherwise - specify the names they know relative to the absolute global domain namespace root, ".". When resolving a hostname, your computer's DNS resolver will look for it in various 'search path' contexts, much like a shell looks for executables relative to all the directories in your PATH. Asking it to resolve news.ycombinator.com will lead to it looking for news.ycombinator.com., but also maybe trying various connection-specific DNS suffixes your network interfaces have configured, or global search suffixes. Commonly macs, for example, try resolving names within the domain 'directory' of "home." - http://mymacbookpro/ http://mymacbookpro/ will look for a machine called "mymacbookpro.home." as well as "mymacbookpro.home.". But http://mymacbookpro./ http://mymacbookpro./ is specifying the absolute path - the resolver won't look for mymacbookpro.home., only mymacbookpro. Conversely, if you type in http://news.ycombinator.com/ http://news.ycombinator.com/, it will look for a "news.ycombinator.com.home." as well as a "news.ycombinator.com.". Yes, you're right - that is an opening for a spoofing attack if you use a compromised or untrustworthy DNS service on your local network. The root nameservers are just one place your DNS resolver looks to to ask questions like "who is the authoritative DNS server for domain names in .com.?" once it's decided to look up a name like news.ycombinator.com..