DEVWorld 2026

Nico Kempe - The parts of DNS nobody explained to you

18:10 · 07 May 2026 – 08 May 2026 · YouTube

About this talk

This talk covers the domain name system (DNS) and its evolution over time. The speaker, Nikico Kempe, shares insights from his decade-long experience with DNS, explaining its origins from the ARPANET and the need for a more efficient system than the original host.txt file. He describes how DNS uses a delegated structure involving root zones and top-level domains, facilitating a scalable registration process for domain names. The session also highlights technical aspects such as caching mechanisms, DNS security measures like DNSSEC, and real-world implications such as domain disputes managed through the UDRP. Kempe emphasizes DNS as a complex, collaborative framework rather than a simple service, urging attendees to understand its intricacies to effectively manage and secure their domain names.

Full transcript

Perfect. Great. Can you hear me? Perfect. Thank you very much for joining me today. Today I want to talk about the domain name system and the stuff that is or was interesting to me. I have always worked with DNS for I think 10 years now and have had to do a lot with it but it never really made click in its in its hole and there have

been a lot of things a lot of institutions terms and stuff that just didn't make sense to me and so I did some research and tried to really learn more about it and find out as much as I could and I summarized it and want to make you included in this and show you all the stuff that I found interesting and I hope you do too. So,

at first, who am I? My name is Nikico Kempe and I'm the founder of Dashio. We built a domain management platform, but this won't be a sales talk. I won't talk too much about it. Just for some background, if you are further interested in this, you can just check out the QR code in the end. So, I hope you are not too disappointed. This won't be an

AI agent talk but we'll find a solution. Great. Okay. So in the beginning I think it's always great to really understand where topic comes from and for the domain name system the start or the initiation is the Sputnik one that was sent by the Soviets to the as an satellite which was a technological shock for the United States of America. They thought that they maybe are left

behind and founded an organization that is called ARPA. And this organization had the task to develop new technologies and to really get familiar with new stuff. And one of this new things was called the Arpanet. I think a lot of you know this already, but I'll just rewrap it. The Arpanet was the predecessor of the now called Internet. And in this smaller network, there have been a

few sites that have been connected. Those have been four universities. They are illustrated right here. And you can see that this was a bit smaller than the internet today. It has just been a few hosts behind those nodes. And in this network, there has been the issue that some communication has be has to be done between those sites and so that people don't always have to write

some numbers. It haven't been IP addresses at this time but other numbers but the concept was the same and the issue was the same from the domain name system that we know today. And to get rid of this issue that people had to write down those numbers over and over again there has been the solution with using words and those words have been defined in a so-called

host host.txt txt file which was laid down on one central host and this was from Stanford UN from the SRRI, the Stanford Research Institute and on there there was a note that basically handed out a txt file with all of the notes, host names and stuff like that. It had more information than the host txt file that we know today that is lying on a Windows host

for example. It had information about the protocols that are being used, the numbers and also the of course the host name that is being used to connect to them and those have been downloaded by the sites and was only one host which was effectively the bottleneck in this situation since the network grew and grew and new hosts got added. There have been a lot of hosts that

have been there. I think over a thousand at this point and it didn't scale really well since there have been more and more coming in and all of them had to be maintained manually. So someone really sat there and entered them in a text file and had to talk about all the or talk with all the people that may be interested and if there was some duplicate

in there that had been an issue and at this point they had to talk about this. There was no system behind it. So they just had some communication which wasn't really scalable. And DNS was the solution to this issue. Since DNS builds up on delegation, delegation works like this. You have a root zone and this root zone is built up by a few servers that are centralized

and also managed by institutions and are set worldwide. But they are basically not responsible for handing out domain names in general but just for delegating the top level domains and those top level domains those are the ones right here for example net.org.io.de de from DNI for example those top level domains are managed by the root zone and are handed out there and the institution just decides which

top level domains can be added and can be used and in numbers those are at the moment I think 1,590 of top level domains in general so there are a lot and usable of them are a bit more than 1,400 the huge benefit of this system is that it no longer has to be administered by just one institution but by a lot of them. So the root

zone decides and hands out the delegations to other organizations. For example, the dynit or the bis sign for example. And one great example of why this is a good idea was seen I think two or three days ago. I don't know if you've heard about it but the huge dynic outage where DNSC made some issues. There has basically been an issue where they made some configuration issues

and the entirete zone was yeah particularly offline or not reachable and that only happened to users that are using domains. So google.de the e for example instead of google.com that has the huge benefit that only a few of them are affected effectively if something happens and those top level domains can also have multiple letters so.gov.uk for example is used in the UK zone but it's just a

restricted zone so people that are using that are working in governmental institutions in Germany in the UK or stuff like that they can use those.gov Gaff subdomains, not subdomains, but those top level domains in the second level can use them and have access to a restricted zone that not everyone can just register domains in and use. And in the next layer, we have the registration channel where

my company basically sits in two. So, Dashio is a domain registration platform where end users if for your portfolio projects or a company that just needs a domain for their new startup or one of their next 10 site projects, they go to such a seller or reseller and ask them for the domain name and they have to ensure that certain criterias are met. For example, top level

domains have the have some have some rules like how many domains can you register in just one domain. For example, in I think Finland, not too sure about that, but there are some countries that are restricting this and are saying only five domains per user, for example, or for private address, which was pretty interesting to me. So those rules can differate a lot between all of those

between all of those organizations that are managing those. then there is the layer that is administered by the end user or by the companies that are working on it. This layer is where everyone manages their DNS. So like their subdomains and it addits adds their www subdomain or add some txt records to verify the ownership of your domain stuff like that. to tell you more about top

level domains that we have just talked about there have been only a few I think it have been eight of them.com.org.info and a few more. Those have been basically the core ones until 2012 and in there there has been a use a huge extension where people or companies could apply and could say they want their own domain for their brand. For example, today we have domains like

Google ordeaf from Google for example those domains have been added and they could apply for them and could say we want to invest some money that have been I think 230,000 something like that. They have to spend a bit on it, have to build the infrastructure, have to meet certain criteria. So not everybody that just wants a TLD gets one. But if you want to build one,

you can purchase this, get some criterias, apply, and maybe your own company can use one. And now we are in around 1,200 TLDDs that are actually usable in the GTLD area. and then 200 CCTLDs sorry but what actually happens when you enter a domain that was also pretty interesting for me because I didn't really understand okay it is used by IP config/ flashdns for example that's used

by most of the people if DNS breaks or if something not not works and if you really want to understand it at first when you enter this domain your browser doesn't understand it um except it has already stored the domain. So on browser level you have caching on OS level you have caching and then the next level would be your resolver for example cloudflare with 1.1.1.1 for

example or your ISP they store those records too so all of those are cached and use them and if they don't have those this information they are asking the next layer basically you are asking step by step and if none of those know it in the end you would have to go to the root servers or to servers in front of them that ask then the top

level domains and they send out the records and hand them out back to you. And what also has been pretty unusual to me was how domains can look like. They can't only look like google.com and use just standard letters, but they can also uni code. They can also include emojis in the in the back end. They are built in a different way or they could also only

exist basically on their top level domain. So for example, HTTP um AI for example. So just the top level domain which was pretty interesting to And then the next thing when I talked about the internet service provider when you have a new router sent out to your home and you are browsing you basically use your ISP's default domain name servers. If you want to use your own

ones for example ones of Cloudflare right here then you have some differentiations between them and their functionality. for example, what what stuff is blocked and what is not and how how the encryption works and if it even supports encryption or if it even supports DNS sec. So all those criterias are relevant when you're picking your ISP. And I also like to compare the speed of those. There

are online web pages that you can just use and look at and check out which works the best for your location. For example, the next thing was the UDRP which has been a real life case for the company I worked for previously where we had some issues with a company or with an basically a scammer that registered a domain in our name and published a domain a

website that really looked like ours and scammed people and people called us and asked us about why we are doing such stuff and why we are scamming people And the resolution for this in our case was just to go with the normal legal way and just ask the registry for at first and then afterwards got to a lawyer and stuff like that. And around this time I

also started with really spending time with the domain name system. And I thought that this UDRP is pretty interesting since this is the official way that has been introduced I think in 1990 something like that where people can go to and just go to the central point or those um institutions that have been using this UDRP and just tell them that someone is mis misusing your domain

and those people are actually positioned right there to really make a decision and take those domains down. So the the way of law can take over years where I come from in Germany that would be a long process and a lot of people would be scanned by then. But the UDRP is used to as a a bit longer way and to really get the solution fast and

to get people off the network that are troubling your recognition and trademark and bad face registration. The next thing was DNSC, which was also pretty interesting to me since it never made click for me what exactly it does and where's the benefit of using it. Basically, the domain name system is a best effort system. So, if you type in google.com for example, then you just hope that

you land there. But in reality, you ask all the paths in front of you and the first one that answers the system and says, "Hey, I know google.com is 8.8.8.8 for example, or is 9.99.9 whatever, whichever IP address is broadcasted right there gets accepted. So you could get a an issue with poisoning that has been a bigger issue in the past, but it's still relevant and it's

still nice to implement DNSX since it breaks this chain of trust and uses it and really says that this domain is from you and not from someone else or from the organization that is being used. So right here it looks like this. So in this entire chain you can just see that the the SAC protocol is using the entire way from the root zone to really verify

that you are you and that this domain really exists and is lying and is um owned by you. And if you want to use DNS for your domains, if you have have some private projects or for your company and you don't know if you have them, there are some scanners to check if you are using it already or not. But if you are not, it's actually pretty

easy. You can just go out to your registar and ask for DNSC. There's usually just a button to enable it and then you get some records that you have to add to your DNS resource records. So you get some input that you can add to your resource records and in this table which is pretty great and it's a low hanging fruit. But I think it's like 1

minute or 2 minutes to just edit and it benefits your company or your domain and your overall domain security in general. Next is the caching topic. I've already talked about this a bit. In general, you can think about it like this that every device that sits between you and the and the domain or the the host of the domain sits between it and tries to cach it

so that it goes really fast and it's not the issue from the beginning with this host. txt file where only one host has been asked for what is the IP address or what is the what is the number for this host but there are a lot of hosts between it that try to get your resolution fast and try to answer your your question and your request as

fast as possible so that you don't have to wait a long time I have collected a lot of tools and stuff that are actually really helpful tools like scanners CLI tools online pages you can do some DNS audit of your current domains. All of this information, a lot of RFC's are all on this page. You can just scan the QR code. It's on my homepage and over

there you can just collect them, visit the websites and click through them. I have added as a description to each of those tools. I didn't want to do a demo of all of them, but there is a lot of helpful stuff in there. If you just bookmark this page and come back to it later if you want to, you can benefit from it and can use all

of those all of those tools. And that's it already. I hope you learned something new and didn't just repeat stuff that you already knew. In general, the thing that I want to give you on your way or want to tell you about DNS now that I have spent such long such long time with it is that DNS is not a system and not just one Windows host

that you send your requests to, but that is a negotiated chain of responsibility. That there are a lot of instances between it that are actually responsible for it and that you can use a lot of ways between it to flush your cache or to get get the solution. That's it. I hope you learned something [applause]

From event

DEVWorld 2026

07 May 2026 – 08 May 2026

All event videos
Back to Watch