What is DNS
DNS (Domain Name System) is one of the core services underpinning the Internet: a distributed database that maps human-readable domain names to the IP addresses computers actually use to find each other. Instead of remembering a numeric address for every site or service, users type a name — and DNS resolves it into the address a device needs to actually make the connection.
That mapping is organized through a hierarchical naming architecture, which is what lets DNS manage and resolve domain names consistently across the entire Internet rather than requiring every network to maintain its own private naming scheme. Compared to older host-file-based resolution — where every device kept its own local list of name-to-address mappings — DNS is dramatically more efficient, reliable, and scalable, combining an efficient resolution mechanism, a distributed system architecture, caching for performance, and redundant backup servers into a system that gives users a seamless, "it just works" experience getting online.
How DNS Works
On a network device, DNS support generally starts with DNS relay: rather than the device running its own full recursive resolver, it forwards DNS queries from downstream clients to one or more configured upstream DNS servers — a straightforward, low-overhead way to give a whole network access to name resolution without deploying dedicated DNS infrastructure.
Beyond basic relay, DNS information can be organized into DNS query groups — named collections of specific domain names (like www.example.com) that a device is configured to recognize and track. Rather than treating DNS purely as a pass-through resolution service, grouping domains this way turns domain-name awareness into something the rest of the device's configuration — like security policy — can reference directly.
That's exactly what DNS ACL does: standard access-list rules typically match traffic by source or destination IP address, but a DNS ACL rule can instead match by source or destination DNS group — filtering traffic based on the domain name a client resolved, rather than the resulting IP address. Because IP-based and DNS-group-based matching represent traffic identification in fundamentally different ways, a single ACL rule can't combine both — a rule matches on IP address or on DNS group, not a mix of the two. This matters in situations where an IP-based rule would be fragile: a domain's underlying IP address can change (a CDN reassigning addresses, a service migrating hosts), but the domain name itself — and therefore the DNS-group match — stays valid.
Why DNS is Beneficial
Makes the Internet usable by humans: Domain names are memorable in a way raw IP addresses never could be, and DNS is the translation layer that makes that convenience possible without sacrificing how machines actually route traffic.
Scales through hierarchy and caching: Distributed, hierarchical resolution combined with caching keeps DNS fast and resilient even at Internet scale, rather than depending on a single central lookup service.
DNS relay simplifies network deployment: A device doesn't need to run its own authoritative or recursive DNS infrastructure to give downstream clients working name resolution — relay to an upstream server is enough.
DNS-aware policy is more resilient than IP-only policy: Filtering or controlling traffic by domain name survives the routine IP address changes that would silently break an equivalent IP-based rule.
Redundancy keeps resolution available: Backup DNS servers and caching mean name resolution keeps working even when a single upstream server has a problem.