DNS & Name Resolution

Name Resolution

Computers route traffic using IP addresses, but humans think in names like github.com. DNS (Domain Name System) is the mechanism that translates one into the other - and Linux gives you several layers of control over exactly how that translation happens.

FilePurpose
/etc/hostsStatic hostname → IP mappings (checked first)
/etc/resolv.confDNS server(s) (nameserver)
/etc/nsswitch.confResolution order (hosts: files dns)

The order these three interact matters a lot: /etc/nsswitch.conf is the master switchboard that decides which sources get consulted and in what order (its hosts: line, typically files dns, means "check /etc/hosts first, then fall back to DNS"). So /etc/hosts isn't just a fallback - by default it's checked before any real DNS lookup happens at all.

CommandPurpose
dig example.comFull DNS query
dig +short A example.comJust the answer
host example.comSimple lookup
nslookup example.comInteractive lookup
getent hosts example.comResolve via nsswitch
$ dig +short github.com
140.82.112.3

dig without +short prints a lot more - query timing, which DNS server answered, the record's TTL (how long it can be cached) - useful when debugging why a lookup returns a stale or unexpected answer, not just what it returns.

Warning: Because /etc/hosts is checked before DNS by default, a stale or incorrect line left in /etc/hosts will silently override perfectly correct DNS records with no error or warning - the machine will confidently connect to the wrong address and you'll be debugging "why does this always resolve wrong on this one server" for a while before you think to check that file. When a hostname resolves unexpectedly on one machine but not others, /etc/hosts should be one of your very first checks.