Basic concepts: what is DNS? And DNSSEC?

Every time you type a domain in your browser, DNS connects you to the right server. Here is how it works and how DNSSEC protects it.
Every time you type a domain name into your browser, an invisible system works in the background to connect you to the right server in a matter of milliseconds. This system is called DNS. But DNS doesn’t just make browsing easier: understanding how it works and how to protect it is essential to ensuring the security of your .cat domain.
How does DNS work?
DNS stands for Domain Name System. Its function is to translate IP addresses — which are very difficult to remember and are what computers interpret — into readable names. For example: 159.69.179.129, which corresponds to the domini.cat website.
The process works like this: when you enter an address in your browser, the query reaches a DNS resolver, which queries different DNS servers until it finds the correct IP address and connects you to the content. The whole thing happens in milliseconds, completely transparently for the user.
Want to see the process step by step? This video explains it very clearly.
DNS has vulnerabilities
DNS was designed to be fast and efficient, but not necessarily secure. The IP addresses it manages are not encrypted, making them accessible to anyone who requests them. This lack of protection opens the door to attacks such as DNS hijacking: a technique in which DNS responses are manipulated to redirect users to fraudulent or malware-infected pages, without them realising.
What is DNSSEC and how does it help you?
DNSSEC, Domain Name System Security Extensions, is an extension of DNS that adds a fundamental security layer: digital signatures. Thanks to this system, each DNS record carries a signature that allows verification that the information is authentic and has not been modified in transit.
DNSSEC uses public key cryptography: a private key signs the records and a public key allows their authenticity to be verified. In this way, even if someone tries to manipulate DNS responses, the system detects and blocks it.
For DNSSEC to work correctly, three conditions must be met: your registrar must allow it to be activated, the domain must be digitally signed, and DNS resolvers must validate the signatures.
DNS makes you visible, DNSSEC keeps you safe
Having a .cat domain is the first step towards building your digital identity. Protecting it is the second. The .cat domain is compatible with DNSSEC: all you need to do is request it from your registrar to ensure that users who visit your domain do so in a safe and trustworthy environment.



