The System Behind Every Click: What DNS Is and Why It Deserves Your Attention

Approx. Reading Time: 6 minutes

On 4 October 2021, Facebook vanished from the internet. Not hacked. Not a power cut. A routine maintenance change went wrong, and for about six hours the internet lost the ability to look Facebook up. Instagram and WhatsApp went with it.

The strangest part is that Facebook’s platforms were still running the whole time. As its engineers explained afterwards, the rest of the internet simply had no way to find them. Reporting at the time described staff locked out of buildings and meeting rooms because the door systems leaned on the same infrastructure. One of the most sophisticated technology companies on the planet spent an afternoon unreachable, and the culprit was a system most business leaders have never heard of: DNS.

The System You Only Notice When It Breaks

Most people meet DNS the way they meet a water main: only when it bursts. It has no logo, no login screen and no line in the budget, yet every website visit, every email, every video call and every cloud application your business touches starts with it. Before your accounting software loads, before a quote reaches a customer, before the payment terminal talks to the bank, a DNS lookup happens first. Dozens of them, usually, in less time than a blink.

When Netier ran an internal workshop on DNS recently, the most striking discovery wasn’t technical. It was how many capable, senior people had never needed to know what DNS is. That isn’t a gap in anyone’s education; it’s a compliment to the system. DNS is designed to be invisible, and for decades it has been reliable enough that entire careers run on top of it without a second thought. 

Invisible when it works. Impossible to ignore when it fails.

What Is DNS?

DNS stands for Domain Name System, and the easiest way to understand it is as the internet’s address book. People remember names: netier.com.au, google.com, your bank’s website. Computers work with long strings of numbers. DNS translates one into the other, billions of times a day, so that typing a name takes you to the right place.

Your business owns one of those names: its domain. And here is the part that surprises people: the domain isn’t just the website. Your email addresses end in it. Your customers trust invoices and quotes that come from it. Many of your cloud applications, logins and integrations quietly depend on entries published under it. The address book entries attached to your domain tell the world where your website lives, who is allowed to send email in your name and which services genuinely belong to you.

Lose control of the domain, or let those entries go wrong, and everything built on top of it wobbles at once. The website is the shopfront. The domain is the deed.

dns

When the Address Book Fails

Facebook’s six-hour disappearance is the famous example, but it isn’t the scariest one, because Facebook at least controlled its own fate. In October 2016, criminals pointed a flood of traffic from an army of hijacked devices, mostly cheap internet-connected cameras and video recorders, at a company called Dyn. Few people had heard of Dyn, but Twitter, Netflix, Spotify and Reddit all relied on it for DNS. Their systems were perfectly healthy. Their customers still couldn’t reach them, in waves, for hours at a stretch through the day. Someone else’s DNS turned out to be their outage. 

And it still happens to the biggest players. In October 2025 it was Amazon’s turn: by AWS’s own account of the incident, a fault in the automated system that manages DNS for one of its core services left a single entry blank, and the disruption cascaded for the better part of a day. It reached some of the world’s best-known apps, banks and payment services, most of which had no idea their fortunes were tied to one entry in one address book in Northern Virginia. 

Facebook. Twitter and Netflix. Amazon. None of them ran out of money or engineers; they ran out of attention, briefly, in exactly the wrong spot. That is the uncomfortable lesson for every organisation: DNS failures are rarely about how much you spend. They’re about whether anyone is looking.

The Quieter Failures

Outages make headlines, but the more common DNS problems are quiet, and they cost real money.

The clearest example is email. Since early 2024 for Google and Yahoo, and 2025 for Microsoft, the world’s big mailbox providers require sending domains to prove who they are, using a handful of entries published in DNS. The checks have ugly acronyms, SPF, DKIM and DMARC, but you don’t need to remember them; you need to know whether yours are set up and working, because the providers no longer extend the benefit of the doubt. Businesses with missing or broken entries are finding their quotes, invoices and reminders drifting into spam folders or being refused outright, while they wonder why customers have gone quiet. An invoice that lands in spam is an invoice that doesn’t get paid. 

Then there is control of the domain itself. Somewhere, there is an account where your domain is registered, with a renewal date and a password. Whoever holds that account effectively holds your website and your email. Domains that lapse because the renewal notice went to a departed employee, or get taken over because that one account had a weak password and no multi-factor authentication, take the brand’s trust down with them. Old, forgotten entries pointing at services you stopped using years ago can quietly hand attackers a way to impersonate you. 

Quiet failures don’t make the news. They just make bad months.

Five Questions to Ask About Your DNS

Here is the good news: compared with almost anything else in technology risk, DNS is cheap to get right. Fixing it rarely involves new hardware or a project budget. It’s configuration and governance: knowing who controls what, checking the entries say what they should, and making sure someone would notice a change. A non-technical leader doesn’t need to touch any of it personally. You just need to ask five questions, and expect confident answers.

Who holds the keys to your domain?

Somebody registered your domain, and somebody pays to renew it. Ask who, through which account, and what happens if that person leaves tomorrow. The account should belong to the organisation, be protected by multi-factor authentication, and be recoverable without archaeology.

Is your DNS hosting resilient?

The Dyn attack taught the internet that even giants can be taken down through a supplier. Ask where the address book entries for your domain are served from, and whether that arrangement would survive a bad day at one provider.

Are your email authentication records in place and enforced?

This is the proof-of-identity conversation from earlier. Ask whether the entries exist, whether they are set to actually enforce anything, and when they were last tested. “It was set up years ago” is not the same as “it works today”.

Would you know if something changed?

DNS changes don’t announce themselves, and attackers count on that. Ask whether anyone is watching your domain’s entries and whether an unexpected change would raise an alert or pass silently. Stale entries deserve the same attention: if nobody is watching, nobody is cleaning up either.

When did you last review any of this?

Address book entries accumulate like drawers full of old chargers: every migration, marketing campaign and software trial leaves something behind. A periodic review is short, unglamorous work that removes whole categories of risk. An afternoon’s review costs less than a day of downtime.

dns

How Netier Can Help

Netier treats DNS and domain governance as business risk, not background plumbing. For managed services clients, that means the unglamorous work is done deliberately: domain ownership and renewals tracked, DNS hosted on resilient infrastructure, email authentication entries in place and enforced, changes watched, and the whole arrangement reviewed rather than left to accumulate. 

The five questions above are the same ones Netier works through with clients, and the answers are usually revealing: not because anyone did anything wrong, but because DNS is exactly the kind of system nobody was ever formally given. For organisations that simply want confidence, a review is a small, contained piece of work with a clear before and after.

Take the First Step

DNS will keep doing its job silently, right up until the day it doesn’t, and that day is a bad one to discover who holds the keys. If nobody in your organisation can answer the five questions above, or if the answers would take longer than a week to find, that’s worth knowing now rather than during an outage. 

Get in touch with the Netier team to talk through a DNS and domain health review for your organisation.

About the author

Search

Resources

Bouncing back from a cyber attack: Building resilience for a growing business

Services

Netier Managed Services

Managed IT Services

Related blogs

The Human Side of Cybersecurity: Why Security Awareness Is Your Most Underinvested Control

From Reactive to Connected: A Smarter Technology Maturity Path for Construction Businesses

The 4 Technology Foundations That Help Construction Projects Move Forward

Categories