Courses Job Ready Program Fresher Trainings AI For Class 7 to 12 Corporate Training Placements Tutorials
Free Learning Resources

IT Tutorials & Interview Prep

Free guides, interview Q&As, and job responsibility breakdowns — curated by industry veterans to help you crack MNC interviews

247+
Tutorial Articles
17
Topic Categories
100%
Free to Read
← Back to Windows Administration

DNS & DHCP Administration

Windows Administration Last Updated: Sep 30, 2026

1. Introduction to DNS & DHCP

1.1 What is DNS & DHCP?

DNS (Domain Name System) and DHCP (Dynamic Host Configuration Protocol) are two core TCP/IP network services that work behind the scenes every time a device connects to a network. DNS translates human-friendly domain names, such as www.google.com, into the numeric IP addresses that computers use to communicate. DHCP automatically assigns IP addresses and other network configuration details — subnet mask, default gateway, DNS servers — to devices as soon as they join a network, removing the need for manual configuration on every machine.

Easy Hinglish Explanation:

DNS ek 'phonebook' ki tarah kaam karta hai — jo naam (jaise google.com) ko number (IP address) mein badalta hai. DHCP ek 'automatic address distributor' hai jo har naye device ko network join karte hi khud-ba-khud IP address de deta hai, bina kisi manual setting ke.

Day-to-Day Example:

When you type "youtube.com" in your browser and the page loads instantly, DNS just converted that name into an IP address behind the scenes. When your phone connects to a Wi-Fi network and gets internet access within seconds without you typing any IP settings, DHCP just handed it an address automatically.

 

1.2 Why do we use DNS & DHCP?

DNS and DHCP exist to remove two of the most repetitive and error-prone burdens of networking: remembering numeric addresses, and manually configuring every device. Together they make networks scalable, human-friendly, and far easier to administer, especially in environments with hundreds or thousands of devices.

  • DNS lets people use memorable names instead of numeric IP addresses.
  • DHCP eliminates manual IP configuration and the address conflicts that come with it.
  • Centralized administration — DNS zones and DHCP scopes can be managed from one console for an entire organization.
  • Both services support redundancy and failover, so a single server outage doesn't take down the network.
  • They integrate tightly with Active Directory, enabling features like dynamic DNS updates and domain-based device management.

1.3 How does DNS & DHCP work?

DNS works as a distributed, hierarchical database. When a client needs to resolve a name, it queries a DNS resolver, which — if it doesn't already know the answer — walks the DNS hierarchy from root servers down to the authoritative name server for that domain, and returns the IP address. DHCP works through a client-server exchange: when a device joins a network, it broadcasts a request for configuration, and a DHCP server responds by leasing it an IP address, along with the subnet mask, gateway, and DNS server addresses, for a fixed period of time called the lease duration.

Fig 1.1 — How a Client Gets Online: DHCP then DNS

1.4 When is DNS & DHCP used?

DNS is used continuously, every time any application — a browser, an email client, an app on a phone — needs to reach a server by name; it is silently invoked dozens of times a day. DHCP is used at the specific moment a device joins or rejoins a network — at boot-up, when Wi-Fi is toggled on, when a laptop moves from one office to another, or when a lease is due for renewal.

Easy Hinglish Explanation:

DHCP tab kaam aata hai jab koi bhi device network se pehli baar connect hota hai ya wapas connect hota hai — jaise laptop restart hone par. DNS to har waqt use hota hai, jab bhi aap koi website ka naam type karte ho ya app internet use karta hai.

 

Day-to-Day Example:

A student's laptop requests a fresh IP address from DHCP every morning when it connects to the college Wi-Fi. Once online, every single website the student visits during the day — Google, YouTube, the college portal — is reached only after a DNS lookup resolves its name to an IP address.

1.5 Where is DNS & DHCP used?

  • Home networks — the Wi-Fi router usually runs a small built-in DHCP server and forwards DNS queries to the ISP.
  • Corporate networks — Windows Server DNS and DHCP roles centrally manage hundreds or thousands of endpoints.
  • Data centers & cloud environments — DNS load-balances traffic across servers; DHCP (or static addressing) manages virtual machine networking.
  • ISP networks — DHCP assigns public IPs to home routers; DNS resolves the entire public internet.
  • Educational institutions — computer labs rely on DHCP for quick device onboarding and DNS for internet/intranet access.

1.6 Who manages DNS & DHCP?

DNS at the global level is coordinated by ICANN and regional internet registries, which oversee the root and top-level domain servers, while individual organizations manage their own internal DNS zones. DHCP is entirely managed within an organization — typically by network or systems administrators who configure scopes, reservations, and lease policies on Windows Server, Linux (ISC DHCP/Kea), or router-based DHCP services.

Easy Hinglish Explanation:

Global level par DNS ko ICANN jaisi organizations manage karti hain, lekin company ke andar ka DNS aur DHCP hamesha ek Network/System Administrator hi sambhalta hai — jo IP ranges, scopes, aur DNS records set karta hai.

Day-to-Day Example:

A company's IT administrator opens the DHCP console every time a new department is added, to create a new scope of IP addresses for that floor's computers — that is DHCP being actively managed by a human administrator.

2. Evolution of DNS & DHCP — Standards History

Both services trace back to earlier, less scalable mechanisms and were formalized through IETF RFCs. The table below captures the key milestones that shaped modern DNS and DHCP administration.

YearMilestoneKey Highlight
1983DNS introduced (RFC 882/883)Replaced the single shared HOSTS.TXT file with a distributed, hierarchical naming system.
1987DNS refined (RFC 1034/1035)Defined the modern DNS architecture still used today — zones, resource records, and queries.
1993BOOTP predecessor to DHCPProvided static boot configuration but lacked automatic, dynamic address leasing.
1993DHCP introduced (RFC 1531)Extended BOOTP with dynamic, automatic IP address leasing and reclamation.
1997DHCP standardized (RFC 2131)Defined the DORA process (Discover, Offer, Request, Acknowledge) still used today.
1999DNSSEC proposed (RFC 2535)Added cryptographic signing to protect DNS responses from tampering and spoofing.
2000sDynamic DNS (DDNS) & AD-integrated DNSWindows Server tightly integrated DNS with Active Directory for automatic record updates.
2011+DHCPv6 & IPv6 adoptionExtended DHCP concepts to IPv6 address assignment as IPv4 exhaustion accelerated.

 

Easy Hinglish Explanation:

Pehle DNS ke bina ek hi HOSTS file mein saari websites ke naam-address save hote the, jo bahut mushkil tha jab internet bada hua. Isi tarah DHCP se pehle har machine ka IP address haath se set karna padta tha — DORA process ne isse automatic bana diya.

Day-to-Day Example:

Just as Windows evolved from Windows 1.0 to Windows 11, DNS evolved from a single static file to a global distributed database, and DHCP evolved from manual/BOOTP-style configuration to today's fully automatic lease-based system.

 

3. Features of DNS & DHCP Administration

A well-administered DNS and DHCP setup offers a rich set of features that make networks reliable, secure, and easy to scale.

3.1 Name Resolution (DNS)

DNS servers resolve forward lookups (name → IP) and reverse lookups (IP → name), and can act as caching, recursive, or authoritative servers depending on their role in the resolution chain.

3.2 Automatic IP Addressing (DHCP)

DHCP servers automatically assign IP addresses, subnet masks, default gateways, DNS server addresses, and optional settings such as WINS or NTP servers, all from a centrally configured address pool called a scope.

Easy Hinglish Explanation:

DHCP sirf IP address hi nahi deta — saath mein gateway, DNS server, aur baaki zaroori network settings bhi ek hi baar mein de deta hai, taaki device turant internet use kar sake.

Day-to-Day Example:

When you connect your phone to office Wi-Fi and it instantly shows 'Connected, no internet issues' with full settings applied, that's DHCP delivering the complete configuration bundle in one exchange.

3.3 Zones & Records (DNS)

DNS organizes data into zones — a forward lookup zone maps names to IPs, and a reverse lookup zone maps IPs back to names. Within a zone, resource records such as A, AAAA, CNAME, MX, NS, and SOA records store the actual mapping and configuration data.

3.4 Scopes & Leases (DHCP)

A DHCP scope defines a range of IP addresses available for a specific subnet, along with exclusions, reservations for specific devices, and a lease duration after which a client must renew its address.

3.5 Redundancy & Failover

Production DNS deployments use multiple name servers (primary and secondary, or multiple domain controllers) so a single failure doesn't break resolution. DHCP supports failover configurations (split-scope or hot-standby) so if one DHCP server goes down, another continues issuing leases without interruption.

3.6 Security Features (DNSSEC, DHCP Snooping)

DNSSEC digitally signs DNS records so resolvers can verify responses haven't been tampered with, protecting against cache poisoning and spoofing. On the DHCP side, DHCP snooping (a switch-level feature) blocks rogue DHCP servers from handing out fraudulent configuration to clients on the network.

Easy Hinglish Explanation:

DNSSEC ek digital signature jaisa hota hai jo confirm karta hai ki DNS ka jawaab असli hai, fake nahi. DHCP snooping switch ko yeh sikhata hai ki kaunsa DHCP server 'trusted' hai, taaki koi fake/rogue DHCP server network ko disturb na kare.

 

Day-to-Day Example:

If an attacker plugs in a rogue router broadcasting fake DHCP offers in an office, DHCP snooping on the network switch blocks those fraudulent offers, while DNSSEC would stop a manipulated DNS response from redirecting employees to a fake banking website.

 

4. Important Concepts & Technical Terms

This section explains the key DNS and DHCP terminology every student and administrator should know before moving to advanced configuration.

DNS Zones — Forward & Reverse Lookup

A forward lookup zone resolves a domain name to an IP address (the everyday case). A reverse lookup zone does the opposite — given an IP address, it returns the associated hostname — and is commonly used for logging, troubleshooting, and mail-server verification.

Resource Records (A, AAAA, CNAME, MX, NS, PTR, SOA)

Resource records are the individual entries inside a DNS zone. An A record maps a name to an IPv4 address; an AAAA record maps a name to an IPv6 address; a CNAME record creates an alias to another name; an MX record specifies mail servers; an NS record identifies authoritative name servers; a PTR record supports reverse lookups; and the SOA (Start of Authority) record defines the zone's administrative properties.

Easy Hinglish Explanation:

Resource records DNS zone ke 'entries' hote hain — jaise ek A record naam ko IPv4 address se, aur MX record email server se jodta hai. SOA record us zone ka 'master info card' hota hai.

Day-to-Day Example:

When a company sets up email, they add an MX record pointing to their mail server, and an A record for www so that visitors reach their website — both live inside the same DNS zone file.

DHCP Scope, Lease, and Reservation

A scope is the pool of IP addresses a DHCP server can hand out for a subnet. A lease is the time period for which a client is allowed to use an assigned address before it must renew. A reservation permanently ties a specific IP address to a device's MAC address, so that device always receives the same IP even though addressing is still managed dynamically.

DORA Process

DORA — Discover, Offer, Request, Acknowledge — is the four-step message exchange a client and DHCP server use to negotiate an IP address lease, detailed step by step in Section 5.

DNS Resolver — Recursive vs Authoritative Servers

A recursive resolver is the server a client directly queries; it does the work of walking the DNS hierarchy on the client's behalf and caches the result. An authoritative server is the definitive source for a specific domain's records — it holds the actual zone data and gives the final answer for names within that zone.

5. DORA & DNS Resolution — Step by Step

Understanding exactly how a device gets online — from requesting an address to resolving its first website — is essential for troubleshooting both DHCP and DNS issues.

5.1 DHCP Lease Process (DORA)

  • Step 1 — Discover: The client broadcasts a DHCPDISCOVER message to the network, since it has no IP address yet and doesn't know which DHCP server exists.
  • Step 2 — Offer: One or more DHCP servers respond with a DHCPOFFER, proposing an available IP address and configuration from their scope.
  • Step 3 — Request: The client selects one offer and broadcasts a DHCPREQUEST, asking to formally lease that specific address (this also tells any other offering servers their offer wasn't chosen).
  • Step 4 — Acknowledge: The chosen DHCP server confirms with a DHCPACK, finalizing the lease; the client can now use the IP address, gateway, and DNS settings it received.

 

Fig 5.1 — DORA: DHCP Lease Negotiation

5.2 DNS Query Resolution Process

  • Step 1 — Client Query: The application asks the operating system to resolve a domain name, which first checks the local DNS cache.
  • Step 2 — Recursive Resolver: If not cached, the query goes to the configured recursive resolver (often the ISP's or organization's DNS server).
  • Step 3 — Root Server: The resolver queries a root DNS server, which points it to the correct top-level domain (TLD) server, such as .com or .org.
  • Step 4 — TLD Server: The TLD server directs the resolver to the authoritative name server responsible for the specific domain.
  • Step 5 — Authoritative Server: The authoritative server returns the actual IP address for the requested name.
  • Step 6 — Response & Caching: The resolver returns the IP address to the client and caches it locally, so repeated lookups are near-instant until the record's TTL expires.

Fig 5.2 — DNS Query Resolution Flow

 

6. Types / Roles of DNS & DHCP Servers

DNS and DHCP servers can be deployed in several roles, each suited to a different purpose within the network.

RoleBest Suited ForKey Function
Primary (Master) DNS ServerThe zone's original source of truthHolds the writable, editable copy of a DNS zone's records.
Secondary (Slave) DNS ServerRedundancy & load distributionHolds a read-only copy replicated from the primary via zone transfer.
Caching-Only DNS ServerSpeeding up repeat lookupsResolves and caches queries but is not authoritative for any zone.
Forwarder DNS ServerControlling external resolutionForwards queries it cannot answer to another specified DNS server (e.g., ISP).
DHCP Server (Standalone)Small networks or branch officesIndependently manages one or more scopes for a subnet.
DHCP Failover PartnerHigh-availability enterprise networksWorks with a partner server to keep issuing leases if one server fails.

7. Important Difference / Comparison Tables

These comparison tables highlight the distinctions most commonly asked about in exams and interviews related to DNS and DHCP.

 

7.1 DNS vs DHCP

BasisDNSDHCP
Primary JobTranslates domain names into IP addresses.Assigns IP addresses and configuration to devices.
Protocol/PortUses UDP/TCP port 53.Uses UDP ports 67 (server) and 68 (client).
Data ManagedZones and resource records (A, MX, CNAME, etc.).Scopes, leases, and reservations.
When It ActsEvery time a name needs to be resolved.When a device joins, renews, or leaves a network.

7.2 Forward Lookup Zone vs Reverse Lookup Zone

BasisForward Lookup ZoneReverse Lookup Zone
DirectionName → IP address.IP address → name.
Common RecordA / AAAA records.PTR records.
Typical UseEveryday website/app access.Logging, troubleshooting, mail server checks.

7.3 Recursive vs Iterative DNS Query

BasisRecursive QueryIterative Query
Who Does the WorkThe queried server does all the follow-up lookups itself.The queried server gives its best answer or a referral, leaving further lookups to the client.
Typical RequesterClient to its local/recursive resolver.Resolver to root, TLD, and authoritative servers.
ResponseFinal IP address is returned.May return a referral to another server instead of the final answer.

7.4 DHCP Reservation vs Static IP vs Dynamic IP

BasisDHCP ReservationStatic IPDynamic IP
Assigned ByDHCP server, tied to MAC address.Manually configured on the device.DHCP server, from the available scope.
ConsistencyAlways the same IP, centrally managed.Always the same IP, but managed per device.Can change after lease expiry.
Best ForPrinters, servers needing a fixed address.Core servers or network devices.General end-user devices.

 

Easy Hinglish Explanation:

DHCP reservation matlab DHCP server khud fix IP deta hai ek device ko uske MAC address ke basis par — isse manually set karne ki zaroorat nahi padti, aur dynamic IP ki flexibility bhi bani rehti hai.

Day-to-Day Example:

An office printer is given a DHCP reservation so it always gets 192.168.1.50, letting every employee's computer print reliably without the IP ever changing — even though the printer never had a manually configured static address.

8. Scenario-Based Questions (Practice)

These questions test your practical understanding of DNS and DHCP administration. Try answering them yourself first, then check the given answer and reasoning.

Q1. A user's laptop cannot reach any website by name, but pinging an IP address directly works fine. What is most likely broken?

Answer: DNS resolution is broken while basic IP connectivity works.

Why / Reason: Since pinging by IP succeeds, the network path is fine; failure only when using names points to a DNS server that is unreachable, misconfigured, or returning no response.

Q2. A new employee's PC shows an IP address starting with 169.254.x.x and has no internet access. What does this indicate?

Answer: The PC failed to get a lease from the DHCP server and fell back to APIPA (Automatic Private IP Addressing).

Why / Reason: 169.254.x.x is the reserved APIPA range Windows assigns itself when no DHCP server responds, meaning the DHCP server is down, unreachable, or out of addresses.

Q3. Two computers on the same subnet were accidentally given the identical static IP address, causing intermittent connectivity for both. How would DHCP have prevented this?

Answer: By using DHCP reservations or dynamic scope-based assignment instead of manual static addressing.

Why / Reason: DHCP centrally tracks which addresses are already leased, so it will not hand out an address that is already in use, eliminating the IP conflict that manual static assignment allows.

Q4. A company wants employees typing 'intranet.company.com' to always reach the internal HR portal server. What DNS record should the administrator create?

Answer: An A record (or CNAME, if pointing to another existing name) for intranet.company.com.

Why / Reason: An A record directly maps that friendly name to the HR portal server's IP address, letting employees use a memorable name instead of remembering the server's IP.

Q5. An organization wants to make sure DHCP keeps working even if one DHCP server crashes. What should the administrator configure?

Answer: DHCP failover (or split-scope configuration) between two DHCP servers.

Why / Reason: Failover lets a partner server continue issuing and renewing leases automatically if the primary server goes offline, avoiding a total loss of address assignment.

Q6. A security team is worried about attackers spoofing DNS responses to redirect users to fake websites. What DNS feature should they enable?

Answer: DNSSEC (Domain Name System Security Extensions).

Why / Reason: DNSSEC cryptographically signs DNS records, allowing resolvers to verify a response genuinely came from the authoritative source and wasn't tampered with in transit.

9. Interview Questions

9.1 Basic Interview Questions

1. What is DNS and why is it needed?

DNS (Domain Name System) translates human-readable domain names into IP addresses, so users can access websites and services by name instead of memorizing numeric addresses.

2. What is DHCP and what problem does it solve?

DHCP (Dynamic Host Configuration Protocol) automatically assigns IP addresses and network configuration to devices, eliminating manual setup and preventing address conflicts.

3. What is the difference between a forward lookup zone and a reverse lookup zone?

A forward lookup zone resolves names to IP addresses, while a reverse lookup zone resolves IP addresses back to names, typically using PTR records.

4. What is the DORA process in DHCP?

DORA stands for Discover, Offer, Request, and Acknowledge — the four-message exchange a client and DHCP server use to negotiate and confirm an IP address lease.

5. What is a DHCP scope?

A DHCP scope is a defined, contiguous range of IP addresses (with exclusions and options) that a DHCP server is authorized to lease out to clients on a specific subnet.

6. What is the difference between an A record and a CNAME record?

An A record maps a name directly to an IPv4 address, while a CNAME record maps a name to another domain name (an alias), which is then resolved further.

7. What port numbers do DNS and DHCP use?

DNS primarily uses port 53 (UDP and TCP); DHCP uses UDP port 67 on the server side and UDP port 68 on the client side.

8. What is a DHCP reservation?

A DHCP reservation permanently assigns a specific IP address to a device's MAC address, so that device always receives the same address while remaining centrally managed by DHCP.

9. What is DNSSEC?

DNSSEC is a set of extensions that digitally sign DNS records, allowing resolvers to verify the authenticity and integrity of DNS responses and prevent spoofing.

10. What is the difference between a recursive and an authoritative DNS server?

A recursive server performs lookups on behalf of a client, querying other servers as needed, while an authoritative server holds the actual zone data and gives the definitive answer for its domain.

9.2 Practical / Scenario-Based Interview Questions

1. How would you troubleshoot a client that cannot obtain an IP address from DHCP?

Check that the DHCP server and its service are running, confirm the scope isn't exhausted, verify DHCP relay/IP helper is configured if the client is on a different subnet, and check the client's network adapter and cabling/Wi-Fi connectivity.

2. A user reports that 'the internet is down' but you find they can reach IP addresses directly. What would you check first?

Verify the client's configured DNS server addresses, confirm the DNS server is reachable and running, and check whether DNS queries are timing out or being blocked by a firewall.

3. How would you migrate DHCP scopes from one Windows Server to another with minimal downtime?

Export the existing scopes with netsh or PowerShell (Export-DhcpServer), deactivate the old server's scopes, import them on the new server, activate them there, and update DHCP relay/router settings to point to the new server's IP.

4. Why might an administrator configure DNS forwarders instead of letting a server resolve everything recursively?

Forwarders let a server send external queries to a chosen upstream resolver (such as the ISP's), reducing external traffic, improving performance through the upstream cache, and giving administrators control over how external name resolution is handled.

5. A company's internal DNS zone isn't updating automatically when devices get new DHCP-assigned addresses. How would you fix this?

Enable and configure Dynamic DNS (DDNS) updates on the DHCP server so it automatically registers and updates DNS A/PTR records for clients whenever a lease is issued or renewed.