DNS is the system that turns a name you can remember into an address a computer can connect to.

This section is about how that actually works, and how to run it safely.

Every lookup starts at the root of the tree and walks down. Each step hands you the address of the next server to ask. Nothing in the chain is guessed, and nothing is built in except the very first step.

These posts cover:

The Active Directory posts assume Samba as the domain controller and BIND as the DNS server. The ideas apply to a Microsoft domain controller too.