- Meaning
- Domain Name System
- Function
- Translates domain names into IP addresses
- Role
- Critical internet infrastructure
- Link to NIS2
- DNS providers count as digital infrastructure
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is DNS?
The DNS (Domain Name System) works like the phone book of the internet: it translates human-readable domain names (compliancecompass.de, say) into the numeric IP addresses computers need in order to connect. On every visit to a website your machine asks for the matching IP address through several stages – from the resolver via the root and TLD servers to the authoritative name server. That resolution runs in the background in milliseconds and is the basic condition for email, the web and almost every online service to work at all.
Why DNS is critical
If DNS fails or is manipulated, services become unreachable or users land unnoticed on forged pages. Because practically every application depends on name resolution working, DNS counts as a central and often underrated layer of cybersecurity. Safeguards such as DNSSEC (signed answers against manipulation), redundant name servers and monitoring of resolution times therefore belong in any serious Risk management.
Typical DNS risks
- DNS spoofing and cache poisoning (redirection to the wrong servers)
- DDoS attacks on DNS servers that paralyse entire domains
- Hijacking of domain or registrar accounts
- Outages or misconfigurations at the DNS service provider
DNS and NIS2
DNS is critical infrastructure. Annex I to the directive names DNS service providers and operators of TLD name registries expressly under digital infrastructure, and Article 2(2) brings both into scope regardless of size – so they are covered as essential or important entities even when they are small. Organisations that merely buy DNS in carry responsibility too: they have to assess the availability of name resolution as part of their Supply chain security arrangements.
In practice: a mid-sized online retailer becomes the target of a DDoS attack on the name server of its hosting provider. The shop is still online, but its domain no longer resolves – orders break off. Because the outage seriously disrupts the provision of the service, the company works through the NIS2 reporting chain: an early warning within 24 hours, a notification with a first assessment within 72 hours and a final report within one month to its competent authority.
Further reading: ICANN – coordination of the global Domain Name System
Frequently asked questions
What does DNS do, in simple terms?
The Domain Name System translates human-readable domain names such as compliancecompass.de into the numeric IP addresses computers need in order to connect – much like a phone book for the internet. On every visit to a website your machine asks for the matching address through several stages, from the resolver via the root and TLD servers to the authoritative name server. Without this name resolution neither email nor the web works.
Why is DNS security-critical?
DNS is security-critical because practically every online application depends on name resolution working. If DNS fails or is manipulated, services become unreachable or users land unnoticed on forged pages. Safeguards such as DNSSEC (signed answers against manipulation), redundant name servers and monitoring of resolution times therefore belong in any serious cybersecurity risk management.
Does DNS fall under NIS2?
DNS service providers and TLD name registries are named expressly under digital infrastructure in Annex I to the NIS2 Directive, which has applied since 18 October 2024. Article 2(2) brings them into scope regardless of their size, so even a small provider is covered and has to meet the risk management and reporting duties and register with the body designated in its Member State. Organisations that merely buy DNS in are affected too: they have to assess the availability of name resolution as part of their supply chain security.