Your domain name is a question.
Every visit relies on an invisible chain of strangers you don't control. Your reachability is borrowed; at any link your name can fall silent—drowned, forged, or rewritten.
You have typed it a thousand times.
The name on your business card. The address bar. The text after the @.
You treat it as a place. Somewhere your site lives, like a building at a street number.
It is not.
Your domain name is a question.
Every time someone reaches you, their machine asks it out loud — and waits for a stranger to answer. The browser does not know where your site lives. It asks a resolver, usually one run by the visitor’s internet provider or by a public service. The resolver, knowing nothing yet, asks a root server: who handles names ending in this extension? There are thirteen root identities, run by twelve organizations across more than a thousand machines, and one of them answers with a referral. The resolver then asks the registry that operates your extension — the organization behind .com, or .hu, or whichever you chose. The registry points to your nameserver. Only at the end of that chain does an answer come back: here is the number, go there.
This runs on every single visit. Most of the links in the chain belong to someone else.
You did not build the root. You do not run the registry. The resolver belongs to your visitor, not to you. You control, at most, the last link — the nameserver — and even that you usually rent from a provider. The system has asked, since its earliest days, that you publish at least two nameservers so the last link is never a single machine. Almost nobody checks whether their two sit in the same building, on the same network, behind the same single account.
Redundancy that shares a single failure is not redundancy.
Then there is what the chain remembers.
Change where your name points, and nothing travels outward. There is no signal that fans across the internet, no master switch that updates the world at once. Each resolver simply keeps the last answer it was handed until the clock on that answer runs out. The clock is the TTL — time to live, a number in seconds that you publish in advance. Set it to a day, and a mistake you make at noon is still being served at midnight. Set it to five minutes, and you can move your whole presence in the time it takes to drink a coffee. The reach of a change is decided before you ever make it.
Nothing propagates — the old answer simply expires.
This is why the careful engineer lowers the TTL days before a migration, long before touching anything that matters. The lever only works if you pull it early.
The stranger your visitor asks is not even one you picked.
Most people now reach the internet through a handful of public resolvers — Google’s 8.8.8.8, Cloudflare’s 1.1.1.1, whatever their device or provider sets by default.
Your visitor’s speed, the freshness of the answer they get, even whether they reach you at all, depend on a machine you have no contract with and cannot see.
When the chain works, none of this is visible. When it breaks, it tends to break for everyone at once.
It has broken, in public, in ways worth remembering.
On 21 October 2016 attackers aimed a botnet of hijacked cameras and baby monitors at a single DNS provider, Dyn. For hours, users across Europe and North America could not reach Twitter, Spotify, Reddit, PayPal, Netflix, or GitHub. Those companies were fine. Their servers never went down. The question simply went unanswered, because the machine whose job was to answer it had been buried under junk traffic.
Five years later the failure ran the other way. On 4 October 2021 a routine maintenance command inside Facebook accidentally cut its data centers off from its own backbone network. Facebook’s nameservers, by design, withdrew themselves from the internet’s routing map the moment they could no longer reach home. In Facebook’s own words, the servers “became unreachable even though they were still operational.” Facebook, WhatsApp and Instagram vanished for roughly six hours — not because the answerers were attacked, but because they took themselves off the map and no one could find them to ask. The same failure locked Facebook’s own engineers out of the internal tools they needed to fix it, and sent a global flood of retries at the public resolvers, which saw DNS traffic spike many times over.
One answerer drowned. The other disappeared. The names behind some of the largest companies on earth went silent either way.
And the answer does not even have to be true.
A resolver believes what it is told.
The original protocol protected each question with a number only sixteen bits wide — about sixty-five thousand possibilities, few enough to guess at speed. In 2008 the researcher Dan Kaminsky showed how an attacker could exploit that narrow gap to slip a forged answer into a resolver’s cache and make it stick — pointing a perfectly valid name at a server the attacker controlled. The industry shipped a fix on a single coordinated day, but it widened the guessing game rather than ending it.
The real repair is DNSSEC, which signs answers cryptographically so a resolver can tell a real one from a forgery.
More than fifteen years on, most of the names you use every day are still unsigned. For those, the chain runs on trust: whoever answers first, and convincingly enough, is believed.
That is the quiet danger. A stranger can answer in your name, and the visitor has no way to tell.
There is one link deeper than all of these.
Every answer in the chain begins as a record someone set — in an account, at a registrar, under a registry. Control that account, and you do not need to attack anything.
You change the answer at its source, and the whole internet, dutifully, begins handing out your new one. In 2019 ICANN warned of exactly this: a campaign that rewrote the records behind targeted names to reroute their traffic. No servers were breached. The answer was simply changed where it is written.
Your reachability is a chain of answers, and you hold almost none of the links.
Decision-makers buy redundancy for the things they can see. Two power feeds. Two data centers. Spare bandwidth. The name that points to all of it usually runs through one provider, on one account, secured by one password, handing out one answer with no spare. The single most load-bearing object in the company sits in the one place no one was asked to defend.
The work, once you see the chain, is unglamorous and specific.
Use more than one DNS provider, so that one provider’s bad day is not automatically your own.
Guard the registrar and registry account harder than you guard the servers, because that account is the source of every answer the world will give about you.
Turn on every lock the registrar offers, put that account behind multi-factor authentication, and tie it to a contact address that won’t walk out the door when someone leaves.
Watch the expiry date the way you watch payroll, because a name allowed to lapse is answered, within minutes, by whoever was waiting for it to fall.
Lower the TTL before you move, not after. Know which stranger speaks for you — and know who is allowed to change what they say.
None of it is exotic. It is just ownership.
The name on your card was never the place you live.
It is a promise that when a stranger asks for you, someone will answer in your name.
The only thing worth knowing is who you have trusted to speak for you — and whether, on the day that voice is drowned, withdrawn, forged, or quietly rewritten, anyone is left who can still answer.
Magyar változat: [zona.hu/a-domainnev-egy-kerdes/]


