Imagine a vast medieval kingdom, sprawling and chaotic, where every lord keeps a stronghold somewhere, but no one quite remembers where. A villager wishes to send word to Sir Google's castle. All she knows is his name. She does not know which mountain his keep sits on, which road leads to his gates, or even what realm he calls home.

This is the predicament every traveler on the internet faces. Names are easy to remember. Addresses are not.

the royal registry

Long ago, a wise council of scholars established the Royal Registry: a great archive that maps every lord's name to the location of his stronghold. Whenever a peasant wishes to send a message to google.com, she first dispatches a herald to consult the Registry. "Pray tell, kind clerk, where doth Sir Google reside?"

The clerk consults his scrolls and replies: "Sir Google's stronghold lies at the coordinates 142.250.74.46."

The peasant now knows where to send her actual messenger. This Registry is what mortals call DNS, the Domain Name System.

the hierarchy of scribes

The Registry is too vast for any single clerk to know every lord. So it is organized like a feudal hierarchy.

At the top sit the root scribes: thirteen ancient archivists who do not know where any specific lord lives, but who know which guild handles which kingdom. Ask them about google.com and they reply: "Such matters fall under the .com guild. Visit their hall."

The .com guild holds the registry of every stronghold ending in .com. They do not know Sir Google personally, but they keep track of who does. "For matters concerning Sir Google," they say, "consult his personal scribe, the authoritative nameserver."

Finally, Sir Google's own scribe knows everything about his master's lands. "His main keep," the scribe declares, "is at 142.250.74.46. His westward outposts are at..." and so on.

Three consultations. Three scrolls. One address.

the village messenger's shortcut

A clever village messenger does not consult the Royal Registry every time someone mentions Sir Google. That would be tedious. Instead, he keeps a little notebook (his cache) and scribbles down every address he learns.

"Sir Google? I asked yesterday. He's at 142.250.74.46. No need to ride to the Registry."

This notebook has a strict rule: every entry expires. A lord's residence might change. A keep might burn down. New outposts may rise. So each address comes with a time‑to‑live, a date after which the messenger must ask the Registry again.

Browsers, operating systems, internet service providers: each one keeps its own little cache, layered atop the next, like a bureaucracy of scribes copying one another's notes.

when the registry lies

Sometimes a villain intercepts a herald and slips him a false scroll. "Sir Google's stronghold? Why, it lies at 6.6.6.6, a dark fortress controlled by my master." The trusting villager rides off and is robbed at the gate.

This is called DNS poisoning. To guard against it, the kingdom has developed DNSSEC: cryptographic seals on every scroll, so the herald can verify the Registry's answer was truly written by the proper scribe and not forged by a bandit on the road.

Many lords have not bothered to seal their scrolls. The kingdom is still figuring this part out.

a closing note

Every time you type a name into a browser, this entire ritual unfolds. A cascade of heralds, scribes, and dusty registries, all answered in milliseconds, then forgotten until the next request.

The internet, beneath the smooth glass of your screen, is a kingdom of small bureaucracies. DNS is the first office you visit, every time you go anywhere at all.

Next time: the couriers who deliver your actual message, and why some of them never arrive.