DNS & Name Resolution
Name Resolution
Computers route traffic using IP addresses, but humans think in names like github.com. DNS (Domain Name System) is the mechanism that translates one into the other - and Linux gives you several layers of control over exactly how that translation happens.
| File | Purpose |
|---|---|
/etc/hosts | Static hostname → IP mappings (checked first) |
/etc/resolv.conf | DNS server(s) (nameserver) |
/etc/nsswitch.conf | Resolution order (hosts: files dns) |
The order these three interact matters a lot: /etc/nsswitch.conf is the master switchboard that decides which sources get consulted and in what order (its hosts: line, typically files dns, means "check /etc/hosts first, then fall back to DNS"). So /etc/hosts isn't just a fallback - by default it's checked before any real DNS lookup happens at all.
| Command | Purpose |
|---|---|
dig example.com | Full DNS query |
dig +short A example.com | Just the answer |
host example.com | Simple lookup |
nslookup example.com | Interactive lookup |
getent hosts example.com | Resolve via nsswitch |
$ dig +short github.com
140.82.112.3
dig without +short prints a lot more - query timing, which DNS server answered, the record's TTL (how long it can be cached) - useful when debugging why a lookup returns a stale or unexpected answer, not just what it returns.
Warning: Because/etc/hostsis checked before DNS by default, a stale or incorrect line left in/etc/hostswill silently override perfectly correct DNS records with no error or warning - the machine will confidently connect to the wrong address and you'll be debugging "why does this always resolve wrong on this one server" for a while before you think to check that file. When a hostname resolves unexpectedly on one machine but not others,/etc/hostsshould be one of your very first checks.