What Is DNS? Complete Domain Name System Guide for Beginners

Every time you open a website such as example.com, your browser eventually needs to communicate with a server identified by an IP address.

But humans generally prefer remembering names rather than numerical addresses.

This is where DNS comes in.

Simple Definition: DNS stands for Domain Name System. It translates domain names such as example.com into IP addresses and also provides other information used to locate and route services on the internet.

DNS is one of the fundamental systems behind the internet. Without it, users would have to remember IP addresses for many websites and online services.

What Does DNS Do?

At its simplest, DNS helps map a domain name to information needed to reach a service.

For example:

www.example.com
       |
       | DNS lookup
       v
203.0.113.25
  

The browser can then use the resulting address to establish network communication with the destination.

DNS can also provide other records, such as information about mail servers, aliases, and domain verification.

Why Do We Need DNS?

Computers communicate using network addresses, while websites are easier for humans to remember using domain names.

Imagine having to remember an IP address for every website you use:

Website A → 203.0.113.25
Website B → 198.51.100.42
Website C → 192.0.2.10
  

Remembering names is much easier:

example.com
blog.example.com
api.example.com
  

DNS provides the translation and service-discovery layer between human-friendly names and network infrastructure.

DNS in One Simple Diagram

User enters:

https://www.example.com

        |
        v

      Browser
        |
        v

    DNS Resolver
        |
        v

   DNS Infrastructure
        |
        v

    IP Address
        |
        v

   Web Server
        |
        v

   Website
  

What Is a Domain Name?

A domain name is a human-readable name used to identify a domain in the DNS namespace.

Examples include:

  • example.com
  • google.com
  • github.com
  • codewithav.blogspot.com

A domain name can contain multiple labels separated by dots.

Understanding a Domain Name

Consider:

www.example.com
  

It can be viewed as:

www      . example . com
 |            |       |
 |            |       +-- Top-Level Domain
 |            +---------- Domain label
 +----------------------- Subdomain
  

Subdomain

www can be a subdomain label.

Other examples include:

blog.example.com
api.example.com
mail.example.com
  

Domain

example is the domain label in this simplified breakdown.

Top-Level Domain

.com is the top-level domain, commonly called a TLD.

What Is a TLD?

TLD stands for Top-Level Domain.

Common examples include:

  • .com
  • .org
  • .net
  • .edu
  • .gov
  • .in

There are many other generic and country-code top-level domains.

What Is DNS Resolution?

DNS resolution is the process of finding DNS information associated with a domain name.

When your browser needs to connect to a hostname, the system may perform a DNS lookup to find the relevant address.

A simplified flow is:

Domain Name
     ↓
Local Cache
     ↓
DNS Resolver
     ↓
Root DNS
     ↓
TLD DNS
     ↓
Authoritative DNS
     ↓
DNS Answer
     ↓
Client
  

In real systems, caching can cause some of these steps to be skipped because the resolver may already know the answer.

What Happens During a DNS Lookup?

Let's imagine that you enter:

https://www.example.com
  

Your system needs to determine the network address for www.example.com.

Step 1: Browser Cache

The browser may have recently resolved the hostname and may have cached the result.

Step 2: Operating System Cache

The operating system may also have cached DNS information.

Step 3: DNS Resolver

If no usable cached answer is available locally, the query can be sent to a recursive DNS resolver.

Step 4: Resolver Finds the Answer

The resolver can query the DNS hierarchy when it needs to obtain the answer.

Step 5: Result Is Returned

The resolver returns the DNS response to the client and may cache it according to applicable caching rules.

What Is a DNS Resolver?

A DNS resolver, often called a recursive resolver, receives DNS queries from clients and works to find the requested DNS information.

It can communicate with other DNS servers on behalf of the client.

Your Computer
      |
      v
Recursive DNS Resolver
      |
      +---- Root
      |
      +---- TLD
      |
      +---- Authoritative DNS
      |
      v
Answer
  

Resolvers also commonly maintain caches to reduce repeated DNS lookups.

What Is an Authoritative DNS Server?

An authoritative DNS server is a DNS server that provides the authoritative information for a particular DNS zone.

For example, an authoritative server for a domain can hold records such as:

  • A
  • AAAA
  • CNAME
  • MX
  • TXT
  • NS

When a recursive resolver reaches the authoritative source for a domain, it can obtain the relevant DNS record.

Recursive Resolver vs Authoritative DNS Server

Recursive Resolver Authoritative Server
Finds DNS answers for clients Provides authoritative DNS data
Uses caching Hosts zone data
May contact multiple DNS servers Answers for zones it serves

What Is the DNS Root?

At the top of the DNS hierarchy is the root.

The root DNS system helps direct queries toward the appropriate top-level domain infrastructure.

                    Root
                      |
          +-----------+-----------+
          |           |           |
         .com        .org        .in
          |           |           |
          v           v           v
       Domains     Domains     Domains
  

The root system does not normally contain the final IP address for every website. Instead, it helps resolvers discover where information for the relevant TLD can be found.

What Is a TLD DNS Server?

A TLD DNS server handles DNS information for domains under a particular top-level domain.

For example, .com DNS infrastructure helps resolvers locate authoritative nameservers for domains ending in .com.

What Is a DNS Zone?

A DNS zone is an administrative portion of the DNS namespace for which a set of authoritative records is maintained.

A zone can contain records describing how domain names should be resolved.

What Are DNS Records?

DNS records are pieces of information stored in DNS zones.

Different record types serve different purposes.

Important DNS Record Types

A Record

An A record maps a hostname to an IPv4 address.

example.com → 203.0.113.25
  

AAAA Record

An AAAA record maps a hostname to an IPv6 address.

example.com → 2001:db8::25
  

CNAME Record

A CNAME record creates an alias from one hostname to another hostname.

www.example.com
       ↓
example.com
  

CNAME records point to another domain name rather than directly to an IP address.

MX Record

MX records specify mail servers responsible for receiving email for a domain.

example.com
     |
     v
MX
     |
     v
mail.example.com
  

TXT Record

TXT records contain text data associated with a domain.

They are commonly used for purposes such as domain verification and email-related policies.

NS Record

NS records identify authoritative nameservers for a DNS zone.

PTR Record

PTR records are used for reverse DNS, mapping an IP address to a hostname.

DNS Record Comparison

Record Purpose
A Hostname → IPv4 address
AAAA Hostname → IPv6 address
CNAME Hostname alias → another hostname
MX Mail server information
TXT Text-based domain information
NS Authoritative nameservers
PTR Reverse DNS mapping

What Is a Nameserver?

A nameserver is a DNS server that answers DNS queries for a domain or zone.

When you register a domain, the domain's delegation includes nameserver information indicating which authoritative DNS servers are responsible for the domain.

A domain might use nameservers such as:

ns1.example-dns.com
ns2.example-dns.com
  

DNS Delegation

DNS delegation is the process through which responsibility for a portion of the DNS namespace is delegated to authoritative nameservers.

For example:

Root
  ↓
.com
  ↓
example.com
  ↓
Authoritative Nameservers
  

This hierarchical structure allows DNS information to be distributed rather than stored in one enormous database.

What Is DNS Caching?

DNS caching means temporarily storing DNS responses so they can be reused for future requests.

Caching can occur at multiple levels, including:

  • Browser
  • Operating system
  • Local network
  • Recursive resolver

Caching reduces repeated queries and can improve response time.

What Is TTL in DNS?

TTL stands for Time to Live.

In DNS, TTL specifies how long a cached DNS record can generally be retained before it needs to be refreshed according to DNS caching behavior.

For example:

example.com
A
203.0.113.25
TTL: 3600
  

A TTL of 3600 seconds represents one hour.

Why Does DNS Propagation Take Time?

When a DNS record changes, users may not immediately see the new result everywhere because different recursive resolvers can have cached versions of the previous record.

The time required for caches to refresh depends on factors such as the previous TTL and resolver behavior.

This is commonly described as DNS propagation, although DNS changes are essentially being observed as cached information expires and new information is obtained.

What Is Reverse DNS?

Normal DNS commonly maps a hostname to an IP address.

example.com
     ↓
203.0.113.25
  

Reverse DNS performs the opposite type of lookup:

203.0.113.25
     ↓
hostname.example.com
  

Reverse DNS commonly uses PTR records.

DNS and Email

DNS is not only used for websites.

Email systems rely heavily on DNS records.

MX records tell sending mail systems which servers are responsible for receiving mail for a domain.

TXT records can also be used for email-related authentication and policy mechanisms such as SPF, DKIM, and DMARC configurations.

DNS and Subdomains

A single domain can have multiple subdomains.

example.com

├── www.example.com
├── blog.example.com
├── api.example.com
├── mail.example.com
└── shop.example.com
  

Each hostname can have its own DNS records and can point to different services.

DNS and Cloud Computing

DNS plays an important role in cloud environments.

Applications may use DNS for:

  • Websites
  • APIs
  • Load balancers
  • Microservices
  • Cloud storage endpoints
  • Email systems
  • Service discovery

A production architecture might look like:

User
  |
  v
DNS
  |
  v
Load Balancer
  |
  +--------+--------+
  |        |        |
  v        v        v
App 1    App 2    App 3
  |
  v
Database
  

DNS and CDNs

DNS can also be part of how users are directed toward content delivery infrastructure.

Depending on the architecture, DNS can direct users to services that then route traffic through geographically distributed systems or edge infrastructure.

DNS and Cybersecurity

DNS is a major part of security monitoring because malicious infrastructure can use domains and DNS records to support phishing, malware distribution, command-and-control infrastructure, and other attacks.

Security teams may monitor:

  • Suspicious domains
  • Unexpected DNS changes
  • Abnormal DNS query patterns
  • Newly observed domains
  • Large volumes of DNS requests

DNS filtering can also be used as one layer of defensive security.

What Is DNS Spoofing?

DNS spoofing refers broadly to attacks in which false DNS information is supplied to redirect users or systems.

Depending on the attack, a victim may be directed toward an attacker-controlled destination instead of the intended service.

DNS security therefore depends on proper resolver configuration, DNS infrastructure protection, and additional security mechanisms.

What Is DNS Cache Poisoning?

DNS cache poisoning is an attack in which incorrect DNS information is placed into a resolver's cache so that users can receive a fraudulent DNS answer.

Modern DNS infrastructure incorporates mechanisms intended to make such attacks more difficult, and DNSSEC can provide additional authenticity protections for DNS data.

What Is DNSSEC?

DNSSEC stands for Domain Name System Security Extensions.

DNSSEC adds cryptographic signatures to DNS data so resolvers that perform validation can verify that the DNS response originated from the expected DNS data chain and was not improperly modified.

DNSSEC helps address the authenticity and integrity of DNS data.

It does not encrypt ordinary DNS queries or provide general website encryption. HTTPS serves a different purpose.

DNS vs HTTPS

DNS HTTPS
Resolves domain information Protects HTTP communication
Helps locate network services Provides TLS encryption and authentication for web communication
Uses DNS protocols and records Uses HTTP over TLS

What Is DNS over HTTPS?

DNS over HTTPS (DoH) is a method of sending DNS queries through HTTPS.

This can protect the DNS query from being exposed as ordinary plaintext to network observers on the path between the client and the DoH server.

It is different from DNSSEC:

  • DNSSEC focuses on authenticity and integrity of DNS data.
  • DoH transports DNS queries and responses through HTTPS.

What Is DNS over TLS?

DNS over TLS (DoT) is another approach for protecting DNS traffic in transit by sending DNS through a TLS connection.

DoH and DoT solve related transport-privacy problems using different protocols and deployment models.

DNS Ports

Traditional DNS commonly uses UDP port 53.

DNS can also use TCP port 53, including for cases where TCP is required by the protocol or DNS data exchange.

Other DNS-related technologies use different ports. For example, DNS over TLS commonly uses TCP port 853.

How to Check DNS Records

You can inspect DNS information using command-line tools.

Windows nslookup

nslookup example.com
  

Linux dig

dig example.com
  

You can also query specific record types.

dig example.com A
dig example.com AAAA
dig example.com MX
dig example.com TXT
  

Example DNS Lookup Using nslookup

A simplified command is:

nslookup example.com
  

The response can contain information such as the DNS server used and the returned address records.

The exact output depends on the operating system and DNS environment.

Common DNS Problems

1. NXDOMAIN

NXDOMAIN indicates that the queried domain name does not exist according to the responding DNS system.

2. SERVFAIL

SERVFAIL indicates that the DNS server could not successfully complete the query.

Potential causes can include DNSSEC validation issues, upstream failures, or authoritative configuration problems.

3. DNS Timeout

A DNS timeout can occur when the client or resolver does not receive an expected response within the relevant period.

4. Incorrect A or AAAA Record

If an A or AAAA record points to the wrong destination, visitors may be directed to the wrong server.

5. Incorrect Nameservers

If domain delegation points to the wrong nameservers, the intended DNS zone may not be used.

6. Stale Cached Information

Resolvers may temporarily return previously cached information until it expires according to TTL and caching behavior.

How to Troubleshoot DNS Problems

A practical troubleshooting sequence is:

  1. Check the domain name for spelling mistakes.
  2. Query the domain using nslookup or dig.
  3. Check the authoritative nameservers.
  4. Inspect A, AAAA, CNAME, MX, and TXT records as appropriate.
  5. Check the TTL and whether cached information may be involved.
  6. Test using a different recursive resolver.
  7. Check DNSSEC configuration when relevant.
  8. Verify that the destination server is actually reachable.

DNS and Website Hosting

When you connect a domain name to a website, DNS is usually part of the configuration.

A simplified setup might be:

Domain
example.com
     |
     v
DNS A Record
     |
     v
Web Server IP
     |
     v
Website
  

For some hosting platforms, other DNS configurations such as CNAME records or provider-specific records may be required.

DNS and Custom Domains

Suppose you want to connect a custom domain to a blog or web application.

The hosting platform may tell you to create one or more DNS records.

Depending on the platform, these could include:

  • A records
  • AAAA records
  • CNAME records
  • TXT verification records

The exact records should always come from the hosting provider's current documentation.

DNS and Subdomain Architecture

A single domain can provide separate services through subdomains.

example.com
   |
   +-- www.example.com → Website
   |
   +-- api.example.com → Backend API
   |
   +-- app.example.com → Web Application
   |
   +-- mail.example.com → Mail Service
  

This is common in modern application architectures.

DNS and Load Balancing

DNS can participate in traffic distribution, although the actual load-balancing behavior depends on the architecture and service involved.

A DNS name may resolve to infrastructure such as a load balancer rather than directly to an individual application server.

api.example.com
       |
       v
Load Balancer
   /    |    \
  v     v     v
App1  App2  App3
  

Important DNS Concepts to Remember

Concept Simple Explanation
DNS System for resolving domain names and related DNS information
Resolver Finds DNS answers for clients
Authoritative Server Provides authoritative records for a DNS zone
A Record Hostname to IPv4 address
AAAA Record Hostname to IPv6 address
CNAME Alias from one hostname to another
MX Mail server information
TXT Text-based DNS information
TTL Caching lifetime for DNS information

Frequently Asked Questions

```

What is DNS in simple words?

DNS is the system that helps translate domain names into information such as IP addresses so computers can locate network services.

What does DNS stand for?

DNS stands for Domain Name System.

Why is DNS needed?

DNS lets people use memorable domain names instead of having to remember numerical network addresses for websites and other services.

What is DNS resolution?

DNS resolution is the process of finding the DNS information associated with a queried domain name.

What is a DNS resolver?

A DNS resolver receives queries from clients and works to find the appropriate DNS answer, often using cached information and other DNS servers.

What is an authoritative DNS server?

An authoritative DNS server provides the official DNS records for the zones it serves.

What is an A record?

An A record maps a hostname to an IPv4 address.

What is an AAAA record?

An AAAA record maps a hostname to an IPv6 address.

What is a CNAME record?

A CNAME record creates an alias from one hostname to another hostname.

What is an MX record?

An MX record identifies mail servers responsible for receiving email for a domain.

What is TTL in DNS?

TTL, or Time to Live, indicates how long DNS information can generally remain cached before it should be refreshed.

What is DNS propagation?

DNS propagation commonly refers to the time during which different DNS caches still contain previous information after a DNS change.

What is DNSSEC?

DNSSEC is a set of DNS extensions that uses cryptographic signatures to help validating resolvers verify the authenticity and integrity of DNS data.

What is the difference between DNS and HTTPS?

DNS helps resolve domain information, while HTTPS protects web communication using TLS.

What port does DNS use?

Traditional DNS commonly uses port 53 over UDP and can also use TCP. Other protected DNS methods use different transports and ports.

```

Final Thoughts

DNS is one of the most important systems behind the internet.

It provides the naming and discovery mechanism that allows people to use names such as example.com while network infrastructure works with addresses and other machine-readable information.

For developers, network engineers, system administrators, cloud engineers, and cybersecurity learners, DNS fundamentals are essential.

Start by understanding domains, resolvers, authoritative servers, DNS hierarchy, A and AAAA records, CNAME, MX, TXT, nameservers, TTL, caching, and DNS troubleshooting.

CodeWithAV Networking Learning Path:

Domain Names → DNS Resolution → Resolvers → Root → TLD → Authoritative DNS → A/AAAA → CNAME → MX/TXT → TTL & Caching → DNSSEC → DNS Troubleshooting.

Related Articles on CodeWithAV

What Is the Internet and How Does It Work?

What Happens When You Type a URL?

How a Website Works From Browser to Server

HTTP vs HTTPS Explained

HTTP Status Codes Every Developer Should Know

Explore More Networking and Web Development Guides

Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

CodeWithAV — Learn, Discover & Build.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.

HTTP Status Codes Explained: 40+ HTTP Status Codes Every Developer Should Know

When a browser opens a website or an application sends a request to an API, the server returns an HTTP response. One of the most important pieces of that response is the HTTP status code.

You have probably seen codes such as 200 OK, 404 Not Found, 401 Unauthorized, or 500 Internal Server Error.

These codes help clients, developers, monitoring systems, and API consumers understand what happened to a request.

Simple Definition: An HTTP status code is a three-digit number returned by an HTTP server to indicate the result or current state of a request.

Why Are HTTP Status Codes Important?

Status codes provide a standardized way for servers to communicate outcomes.

For example:

GET /api/users/25
        |
        v
   HTTP Server
        |
        v
200 OK
  

A client can use the status code to decide whether a request succeeded, requires another action, failed because of invalid input, or failed because of a server-side problem.

The Five Main HTTP Status Code Classes

HTTP status codes are grouped into five classes based on their first digit.

Range Class General Meaning
100–199 Informational Request received or processing information
200–299 Success Request was successfully handled
300–399 Redirection Further action may be required
400–499 Client Error Request could not be fulfilled due to a client-side issue
500–599 Server Error Server encountered a problem processing the request

HTTP Status Codes Cheat Sheet

Code Meaning Common Use
100ContinueInterim response
101Switching ProtocolsProtocol upgrade
200OKSuccessful request
201CreatedResource created
202AcceptedRequest accepted for processing
204No ContentSuccessful response without a body
301Moved PermanentlyPermanent redirect
302FoundTemporary redirect
304Not ModifiedConditional request has no newer representation
307Temporary RedirectTemporary redirect preserving method
308Permanent RedirectPermanent redirect preserving method
400Bad RequestMalformed or invalid request
401UnauthorizedAuthentication required or failed
403ForbiddenRequest understood but not permitted
404Not FoundResource not found
405Method Not AllowedHTTP method not supported for resource
408Request TimeoutServer timed out waiting for request
409ConflictConflict with resource state
410GoneResource intentionally no longer available
413Content Too LargeRequest body exceeds permitted size
415Unsupported Media TypeUnsupported request format
422Unprocessable ContentContent understood but cannot be processed
429Too Many RequestsRate limit exceeded
500Internal Server ErrorUnexpected server failure
501Not ImplementedServer does not support required functionality
502Bad GatewayGateway received an invalid upstream response
503Service UnavailableService temporarily unavailable
504Gateway TimeoutGateway timed out waiting for upstream

1xx Informational Status Codes

100-level status codes are informational responses. They generally indicate that the request has been received and processing can continue.

100 Continue

The server indicates that the initial part of the request has been received and the client can continue sending the request.

101 Switching Protocols

This response indicates that the server agrees to switch to a different protocol according to the client's request.



2xx Success Status Codes

200-level status codes indicate successful handling of a request.

200 OK

200 OK is one of the most commonly encountered HTTP status codes.

It generally indicates that the request was successfully processed.

Example:

GET /api/users/25

HTTP/1.1 200 OK
  

201 Created

201 Created indicates that a new resource has been created successfully.

It is commonly used after POST requests that create resources.

POST /api/users

HTTP/1.1 201 Created
  

202 Accepted

202 Accepted indicates that the request has been accepted for processing, but processing may not be complete yet.

This can be useful for asynchronous operations.

204 No Content

204 No Content indicates successful processing when the response does not need to contain a message body.

For example, an API might return 204 after successfully deleting a resource.

3xx Redirection Status Codes

300-level status codes indicate that additional action may be required to complete a request.

301 Moved Permanently

301 indicates that a resource has been permanently moved to a different location.

Example:

https://example.com/old-page
        ↓
https://example.com/new-page
  

302 Found

302 Found indicates a temporary redirection in modern HTTP usage.

304 Not Modified

304 Not Modified is used with conditional requests. It tells the client that its cached representation can still be used because the resource has not changed according to the request's conditions.

307 Temporary Redirect

307 Temporary Redirect indicates a temporary redirect while preserving the request method and request body semantics.

308 Permanent Redirect

308 Permanent Redirect indicates a permanent redirect while preserving the request method and request body semantics.

4xx Client Error Status Codes

400-level responses generally indicate a problem with the request from the client side. That does not necessarily mean the person using the client made a mistake; it means the request cannot be fulfilled due to the request or its context.

400 Bad Request

400 Bad Request is commonly returned when the server cannot process a malformed or invalid request.

Example:

POST /api/users

{
  "email": 
}
  

The request body is malformed, so the server may return 400.

401 Unauthorized

401 Unauthorized is commonly used when valid authentication credentials are required but are missing or invalid.

Example:

GET /api/profile

HTTP/1.1 401 Unauthorized
  

Important: The name can be confusing. In API security discussions, 401 generally relates to authentication, not simply permission.

403 Forbidden

403 Forbidden indicates that the server understood the request but refuses to authorize it.

For example, a normal user may authenticate successfully but still receive 403 when trying to access an administrator-only resource.

404 Not Found

404 Not Found means that the server cannot find a current representation for the requested resource.

Example:

GET /api/users/99999

404 Not Found
  

405 Method Not Allowed

405 Method Not Allowed indicates that the request method is known by the server but is not allowed for the requested resource.

For example, an endpoint might support GET but not DELETE.

408 Request Timeout

408 Request Timeout indicates that the server did not receive a complete request within the time it was prepared to wait.

409 Conflict

409 Conflict indicates that the request conflicts with the current state of the target resource.

For example, an API could use 409 when attempting to create a resource that conflicts with an existing unique record, depending on the API design.

410 Gone

410 Gone indicates that the requested resource is no longer available and that the condition is likely to be permanent.

413 Content Too Large

413 Content Too Large indicates that the request content exceeds a limit defined by the server.

This can occur when uploading a file or sending a large request body.

415 Unsupported Media Type

415 Unsupported Media Type indicates that the server does not support the media format of the request.

For example, an endpoint expecting JSON might reject an unsupported request format.

422 Unprocessable Content

422 Unprocessable Content indicates that the server understood the content type and syntax but could not process the contained instructions or data.

For example, a request might contain valid JSON but fail application-level validation.

429 Too Many Requests

429 Too Many Requests is commonly used when the client has sent too many requests within a defined period.

This is especially relevant to APIs that implement rate limiting.

5xx Server Error Status Codes

500-level status codes generally indicate a problem on the server side while processing a valid request.

500 Internal Server Error

500 indicates an unexpected server-side error.

Example:

GET /api/orders

HTTP/1.1 500 Internal Server Error
  

Possible causes include:

  • Unhandled application exceptions
  • Unexpected dependency failures
  • Programming errors
  • Configuration problems

501 Not Implemented

501 Not Implemented indicates that the server does not support the functionality required to fulfill the request.

502 Bad Gateway

502 Bad Gateway usually occurs when a server acting as a gateway or proxy receives an invalid response from an upstream server.

Client
  |
  v
Reverse Proxy
  |
  v
Application Server
  |
  X
Invalid / Failed Response

Proxy → 502
  

503 Service Unavailable

503 Service Unavailable indicates that the server is currently unable to handle the request, often due to temporary overload, maintenance, or another temporary condition.

504 Gateway Timeout

504 Gateway Timeout indicates that a gateway or proxy did not receive a timely response from an upstream server.

Client
  |
  v
Gateway
  |
  v
Backend
  |
  |
  |------ No timely response
  |
Gateway → 504
  

401 vs 403: What Is the Difference?

This is one of the most common interview questions.

401 403
Authentication is missing or invalid Request is understood but not authorized
Identity has not been successfully established Identity may be known, but access is denied
Example: expired or missing credentials Example: normal user requesting admin-only data

404 vs 410

Both codes relate to missing resources, but their meaning differs.

404 Not Found indicates that the server cannot find a current representation for the resource.

410 Gone indicates that the resource is no longer available and that this is intended to be permanent.

500 vs 502 vs 503 vs 504

Code Typical Problem
500 Unexpected internal server problem
502 Gateway/proxy received an invalid upstream response
503 Service temporarily unavailable
504 Gateway/proxy timed out waiting for upstream

HTTP Status Codes in REST APIs

Correct status codes make REST APIs easier to understand and consume.

For example:

GET    /users/10      → 200
POST   /users         → 201
PATCH  /users/10      → 200 or 204
DELETE /users/10      → 204
GET    /users/999     → 404
POST   /users         → 400 / 422
GET    /admin/report  → 401 / 403
GET    /users         → 429
GET    /users         → 500
  

The exact status selected depends on the semantics of the API and its application rules.

HTTP Status Codes and Frontend Applications

Frontend applications can use status codes to decide what to display or what action to perform.

For example:

if (response.status === 200) {
    // Show data
}

if (response.status === 401) {
    // Ask user to log in
}

if (response.status === 403) {
    // Show access denied message
}

if (response.status === 404) {
    // Show not found message
}

if (response.status === 500) {
    // Show generic server error
}
  

This allows applications to handle different outcomes more intelligently.

HTTP Status Codes and JavaScript Fetch

One important detail is that the Fetch API does not automatically reject a promise merely because an HTTP response has a 4xx or 5xx status.

Developers should inspect the response status or the ok property.

fetch("/api/users")
  .then(response => {
    if (!response.ok) {
      throw new Error(`HTTP ${response.status}`);
    }

    return response.json();
  })
  .then(data => {
    console.log(data);
  })
  .catch(error => {
    console.error(error);
  });
  

HTTP Status Codes and API Error Handling

A good API should combine an appropriate status code with a useful response body when additional information is appropriate.

For example:

HTTP/1.1 422 Unprocessable Content
Content-Type: application/json

{
  "error": "validation_error",
  "message": "Email address is invalid",
  "field": "email"
}
  

This is generally more useful to a frontend than returning only a number.

Should You Use 200 for Every API Response?

Using 200 for every situation is generally a poor API design choice.

Status codes exist to communicate meaningful outcomes.

For example, returning 200 for a failed authentication attempt makes it harder for clients, monitoring tools, developers, and intermediaries to understand what happened.

Use status codes according to the semantics of the operation and your API design.

How Developers Debug HTTP Status Codes

When an application returns an unexpected status code, inspect the complete request and response.

Useful information includes:

  • HTTP method
  • Request URL
  • Request headers
  • Request body
  • Status code
  • Response headers
  • Response body
  • Server logs
  • Reverse-proxy logs
  • Application logs

Browser developer tools, Postman, curl, server logs, and monitoring systems can all help identify the cause.

Example: Debugging a 404

Suppose your frontend requests:

GET /api/user/25
  

but the API actually defines:

GET /api/users/25
  

The difference between user and users could result in a 404.

Always check the actual endpoint, routing configuration, base URL, and deployment environment.

Example: Debugging a 401

Suppose a protected endpoint returns 401.

Check:

  1. Whether credentials were included.
  2. Whether the credentials are valid.
  3. Whether the expected authentication scheme was used.
  4. Whether the token has expired.
  5. Whether the server received the authentication header.

Example: Debugging a 403

If authentication succeeds but the server returns 403, inspect authorization rules.

Common questions include:

  • Does the user have the required role?
  • Does the account have the required permission?
  • Is the requested resource restricted?
  • Is a policy blocking the action?

Example: Debugging a 502

A 502 often points to a problem between a proxy and an upstream service.

Browser
   |
   v
Nginx / Reverse Proxy
   |
   v
Node.js / Python / PHP Backend
  

Possible causes can include:

  • Backend process stopped
  • Incorrect upstream address
  • Connection failure
  • Malformed upstream response
  • Deployment problem

Example: Debugging a 503

A 503 can indicate that a service is temporarily unavailable.

Possible causes include:

  • Maintenance
  • Application overload
  • Unavailable backend service
  • Health-check failure
  • Deployment transition

Example: Debugging a 504

A 504 usually means a gateway or proxy waited for an upstream response but did not receive one within the relevant timeout.

Investigate:

  • Backend response time
  • Database performance
  • Network connectivity
  • Proxy timeout configuration
  • Long-running operations

HTTP Status Codes Interview Questions

What does HTTP 200 mean?

It generally means that the request was successfully processed.

What does HTTP 201 mean?

It indicates that a resource was successfully created.

What does HTTP 204 mean?

It indicates successful processing with no response content.

What does HTTP 301 mean?

It indicates that a resource has been permanently moved to another location.

What does HTTP 304 mean?

It indicates that the client's cached representation can be reused because the resource has not changed according to the conditional request.

What does HTTP 400 mean?

It generally indicates that the server could not process the request because it was invalid or malformed.

What is the difference between 401 and 403?

401 generally relates to missing or invalid authentication, while 403 means the request is understood but access is not permitted.

What does HTTP 404 mean?

It means that the requested resource could not be found.

What does HTTP 429 mean?

It indicates that the client has sent too many requests within a relevant time period.

What does HTTP 500 mean?

It indicates an unexpected internal server error.

What does HTTP 502 mean?

It generally indicates that a gateway or proxy received an invalid response from an upstream server.

What does HTTP 503 mean?

It indicates that the server is currently unable to handle the request, often because of a temporary condition.

What does HTTP 504 mean?

It indicates that a gateway or proxy did not receive a timely response from an upstream server.

Frequently Asked Questions

```

What are HTTP status codes?

HTTP status codes are three-digit numbers returned in HTTP responses to communicate the result or state of a request.

How many categories of HTTP status codes are there?

There are five categories: informational (1xx), success (2xx), redirection (3xx), client error (4xx), and server error (5xx).

Which HTTP status code means success?

200 OK is the most common success status code, although other successful codes such as 201 and 204 are used for specific situations.

Which HTTP status code means not found?

404 Not Found indicates that the server cannot find the requested resource.

What is the difference between 401 and 403?

401 generally indicates an authentication problem, while 403 indicates that the request is not authorized.

What does 429 mean?

429 Too Many Requests indicates that a client has exceeded an applicable request rate limit.

What is the difference between 500 and 503?

500 generally indicates an unexpected internal server error, while 503 indicates that the service is currently unavailable and may recover later.

What causes a 502 error?

A 502 often occurs when a gateway or reverse proxy receives an invalid response from an upstream server.

What causes a 504 error?

A 504 occurs when a gateway or proxy waits for an upstream server but does not receive a response within the relevant timeout.

Are HTTP status codes only used for websites?

No. They are also widely used by APIs, backend services, mobile applications, cloud services, proxies, and other HTTP-based systems.

```

Final Thoughts

HTTP status codes are a fundamental part of web development, backend programming, API design, DevOps, and cybersecurity.

You do not need to memorize every status code immediately. Start with the most useful ones:

200  → Success
201  → Created
204  → No Content

301  → Permanent Redirect
302  → Temporary Redirect
304  → Not Modified

400  → Bad Request
401  → Authentication Problem
403  → Forbidden
404  → Not Found
405  → Method Not Allowed
409  → Conflict
422  → Unprocessable Content
429  → Too Many Requests

500  → Internal Server Error
502  → Bad Gateway
503  → Service Unavailable
504  → Gateway Timeout
  

Once these codes become familiar, debugging web applications and REST APIs becomes much easier.

CodeWithAV Developer Tip:

When debugging an API, never look only at the status code. Inspect the request URL, method, headers, body, response body, server logs, and upstream services together.

Related Articles on CodeWithAV

What Is an API? Complete Beginner Guide

REST API Explained With Examples

What Is JSON?

HTTP vs HTTPS Explained

How a Website Works From Browser to Server

Explore More Web Development and Networking Guides

Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

CodeWithAV — Learn, Discover & Build.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.

HTTP vs HTTPS Explained: Difference, Security, Ports & How HTTPS Works

Whenever you open a website, your browser communicates with a server using network protocols. Two terms that frequently appear in web development and cybersecurity are HTTP and HTTPS.

You have probably noticed addresses such as:

http://example.com
https://example.com
  

They look almost identical, but the difference is extremely important.

HTTP stands for Hypertext Transfer Protocol, while HTTPS stands for Hypertext Transfer Protocol Secure.

HTTPS adds cryptographic protection to HTTP communication, helping protect data exchanged between the client and server.

Simple Definition: HTTP transfers web data without the transport encryption provided by HTTPS. HTTPS uses HTTP over a secure TLS connection to protect data in transit.


What Is HTTP?

HTTP is a protocol used for communication between web clients and servers.

When you open a website, your browser can send an HTTP request to a server. The server processes that request and sends an HTTP response.

Browser
   |
   | HTTP Request
   v
Web Server
   |
   | HTTP Response
   v
Browser
  

HTTP is the foundation for exchanging resources such as HTML documents, stylesheets, JavaScript files, images, and API responses.

What Is HTTPS?

HTTPS is HTTP carried over a secure TLS connection.

TLS stands for Transport Layer Security.

HTTPS is designed to provide important security properties for data sent between a client and server, including:

  • Encryption of data in transit
  • Integrity protection
  • Authentication of the server through certificates
Browser
   |
   | Encrypted TLS Connection
   v
Web Server
   |
   | Encrypted TLS Connection
   v
Browser
  

HTTP vs HTTPS at a Glance

Feature HTTP HTTPS
Protocol HTTP HTTP over TLS
Encryption in transit No TLS protection Yes, through TLS
Typical port 80 443
Server authentication No TLS certificate authentication Uses TLS certificates
Data integrity protection Not provided by TLS Provided by TLS

Why Is HTTPS Important?

When sensitive information travels across a network, an attacker who can observe network traffic should not be able to simply read or modify the protected contents.

HTTPS helps protect information such as:

  • Login credentials
  • Session cookies
  • Personal information
  • Payment-related information
  • API requests and responses
  • Private application data

HTTPS is therefore an important part of modern web security.

How Does HTTPS Work?

HTTPS uses TLS to create a protected communication channel between the client and server.

A simplified flow looks like this:

1. Browser connects to website
             ↓
2. Server presents its TLS certificate
             ↓
3. Browser validates the certificate
             ↓
4. Client and server establish cryptographic keys
             ↓
5. Secure TLS connection is established
             ↓
6. HTTP messages travel through that connection
  

The exact cryptographic process is more detailed, but this simplified model helps beginners understand the purpose of TLS.

What Is TLS?

TLS stands for Transport Layer Security.

TLS is a cryptographic protocol designed to secure communication over networks.

HTTPS uses TLS to protect HTTP traffic.

So the relationship can be visualized as:

HTTPS
  |
  +-- HTTP
  |
  +-- TLS protection
  |
  +-- Secure network connection
  

What Is an SSL Certificate?

You may often hear people say SSL certificate when discussing website security.

SSL stands for Secure Sockets Layer. SSL is an older protocol that has been replaced by TLS for modern secure web communication.

The term "SSL certificate" is still widely used to describe the digital certificates used with HTTPS, even though modern systems use TLS rather than the old SSL protocol.

What Is a TLS Certificate?

A TLS certificate is a digital certificate associated with a website's identity and public key.

It helps a browser verify that the server it is connecting to is associated with the requested domain, subject to the certificate validation process and trust model.

Certificates are issued by trusted certificate authorities within the browser or operating system trust ecosystem.

What Does a Browser Check in a Certificate?

Certificate validation involves several checks. Depending on the environment, the browser can verify items such as:

  • The certificate is valid for the requested domain.
  • The certificate is currently within its validity period.
  • The certificate chains to a trusted authority.
  • The certificate has not failed other required validation checks.

If a serious certificate validation problem exists, the browser can warn the user before establishing normal HTTPS trust.

What Is Encryption?

Encryption transforms readable information into a form that cannot be understood without the appropriate cryptographic information needed to decrypt or authenticate it.

For example, a message such as:

Hello Server
  

can be transmitted as protected ciphertext rather than as ordinary readable text.

Modern TLS uses established cryptographic algorithms to provide confidentiality and integrity protection.

What Is Data Integrity?

Integrity means detecting unauthorized modification of data during transmission.

Imagine sending:

amount=1000
  

An attacker should not be able to silently change it to:

amount=9000
  

without the communication endpoints detecting that something went wrong.

TLS provides integrity protection for the protected connection.

What Is Authentication in HTTPS?

HTTPS uses certificates to help authenticate the server.

This is important because encryption by itself is not enough.

Suppose an attacker creates a fake website that looks exactly like a legitimate website. A secure connection alone would not prove that the website is the correct site unless the authentication and certificate checks are also valid.

TLS certificate validation helps the browser establish that the server is associated with the requested domain according to the certificate trust system.

HTTP Port 80 vs HTTPS Port 443

HTTP is conventionally associated with TCP port 80.

HTTPS is conventionally associated with TCP port 443.

HTTP
Browser
   |
   +---- TCP 80 ----> Web Server


HTTPS
Browser
   |
   +---- TCP 443 ---> Web Server
          |
          +---- TLS
  

These are conventional ports, not absolute requirements. Network services can be configured differently.

HTTP Example

A simplified HTTP request could look like:

GET /index.html HTTP/1.1
Host: example.com
  

The server might return:

HTTP/1.1 200 OK
Content-Type: text/html
  

With ordinary HTTP, there is no TLS layer protecting the communication.

HTTPS Example

With HTTPS, HTTP messages are carried inside a TLS-protected connection.

Browser
   |
   | TLS-secured connection
   v
Server

Inside the protected connection:
HTTP Request
HTTP Response
  

The network does not simply see the HTTP application data as ordinary plaintext.

Does HTTPS Encrypt Everything?

No.

HTTPS protects the contents of the TLS connection, but it does not make every aspect of network activity invisible.

For example, information such as IP addresses and certain metadata can still be observable to parts of the network infrastructure.

HTTPS should therefore not be interpreted as complete anonymity.

Can HTTPS Stop All Cyberattacks?

No.

HTTPS protects data in transit, but it does not automatically protect the website from vulnerabilities in its own application or infrastructure.

A website can use HTTPS and still have problems such as:

  • Weak passwords
  • Broken access control
  • SQL injection
  • Cross-site scripting
  • Insecure file uploads
  • Server misconfiguration
  • Vulnerable dependencies
  • Compromised user accounts

HTTPS is one layer of security, not a complete security solution.

HTTPS and Public Wi-Fi

Public Wi-Fi networks can expose users to security risks when applications communicate without adequate transport protection.

HTTPS helps protect the content of web communication from network observers by encrypting the traffic between the client and server.

However, users should still be careful with suspicious websites, phishing pages, malicious downloads, and compromised accounts.

What Is a Man-in-the-Middle Attack?

A Man-in-the-Middle (MITM) attack occurs when an attacker places themselves between two communicating parties and attempts to observe, modify, or interfere with their communication.

TLS helps defend against network-level interception and modification by providing encryption, integrity, and server authentication.

Without Proper Transport Protection

Client <------> Attacker <------> Server
                 |
              Can attempt
             to observe or
              alter traffic


With Proper HTTPS

Client ======== TLS ========= Server
        Protected Connection
  

HTTPS does not protect against every form of attack, but it significantly improves the security of data in transit.

HTTP Redirect to HTTPS

Many websites configure HTTP traffic to redirect users to an HTTPS URL.

For example:

http://example.com
       |
       v
https://example.com
  

A redirect can help move users toward the secure version of a site.

However, the initial HTTP connection is not itself protected by TLS, so secure-site configurations often also use mechanisms such as HSTS to tell compatible browsers to use HTTPS for future connections.

What Is HSTS?

HSTS stands for HTTP Strict Transport Security.

HSTS is a browser security mechanism that allows a website to tell compatible browsers that it should only be accessed through HTTPS for a specified period.

A response can include a header such as:

Strict-Transport-Security: max-age=31536000
  

Real deployment should use HSTS deliberately and according to the site's infrastructure and domain configuration.

HTTPS and Cookies

HTTPS is especially important for applications that use authentication cookies or session information.

Websites can also configure cookie security attributes such as:

  • Secure — directs browsers to send the cookie over secure connections.
  • HttpOnly — helps prevent client-side scripts from directly reading the cookie.
  • SameSite — controls how cookies are sent in cross-site contexts.

These controls complement HTTPS rather than replacing it.

HTTPS and APIs

APIs often handle valuable information, making transport security extremely important.

A secure API might use:

https://api.example.com/users
  

Instead of:

http://api.example.com/users
  

When API requests contain authentication credentials or private information, transmitting them over an unprotected connection can expose those credentials and data to network attackers.

HTTPS in Mobile Applications

Mobile applications also communicate with remote APIs.

A mobile app might send:

POST https://api.example.com/login
  

The TLS connection helps protect the credentials and other application data in transit.

Does HTTPS Affect Website Speed?

Modern TLS implementations are designed to minimize connection overhead, and HTTPS is standard practice for modern websites.

The overall performance of a website depends on many factors, including:

  • Server response time
  • Network latency
  • HTTP protocol version
  • Image sizes
  • JavaScript and CSS
  • Caching
  • Content delivery architecture

Therefore, HTTPS should not be viewed simply as a feature that automatically makes a site slow.

HTTPS and SEO

Website security is important for users and modern web infrastructure. Search engines may also use HTTPS as a ranking-related signal in their systems.

However, switching a website to HTTPS does not guarantee higher search rankings. Content quality, relevance, technical health, user experience, and many other factors also matter.

How to Check Whether a Website Uses HTTPS

Look at the browser's address bar.

A website using HTTPS will generally begin with:

https://
  

Modern browsers may display security information differently, so the exact visual indicator can vary between browsers.

How to Inspect a Website Certificate

Most modern browsers provide certificate and connection details through the site's security information in the address bar or developer tools.

You can use this information to inspect details such as:

  • Certificate subject
  • Certificate issuer
  • Validity period
  • Connection security

HTTP vs HTTPS: Security Comparison

Security Property HTTP HTTPS
Confidentiality No TLS encryption Protected by TLS
Integrity No TLS integrity protection TLS provides integrity protection
Server Authentication No TLS certificate mechanism TLS certificates support authentication

Common HTTPS Misconceptions

Misconception 1: HTTPS Means the Website Is Completely Safe

Not necessarily. HTTPS protects transport between endpoints, but the website can still contain application vulnerabilities.

Misconception 2: HTTPS Means the Website Owner Is Trustworthy

A valid certificate primarily helps authenticate control of the relevant domain within the certificate trust system. It does not guarantee that the site's content, business practices, or offers are trustworthy.

Misconception 3: HTTPS Provides Complete Anonymity

No. HTTPS protects application data in the encrypted connection, but network metadata can still reveal information such as IP addresses and traffic patterns.

Misconception 4: HTTPS Is Only Needed for Payment Websites

HTTPS is useful for all kinds of websites and applications because even ordinary browsing can involve cookies, account credentials, personal data, and private application information.

How Developers Can Enable HTTPS

The exact process depends on the hosting environment, reverse proxy, platform, and certificate setup.

A typical deployment process can include:

  1. Configure the domain.
  2. Obtain a trusted TLS certificate.
  3. Configure the web server or hosting platform.
  4. Enable HTTPS.
  5. Test certificate validation.
  6. Redirect appropriate HTTP traffic to HTTPS.
  7. Configure secure cookies and application settings.
  8. Consider HSTS after the HTTPS configuration is correct.

HTTPS With Nginx

On Linux servers, Nginx is commonly used as a web server or reverse proxy.

A simplified configuration might look conceptually like:

server {
    listen 443 ssl;
    server_name example.com;

    ssl_certificate     /path/to/certificate.pem;
    ssl_certificate_key /path/to/private-key.pem;

    location / {
        proxy_pass http://127.0.0.1:3000;
    }
}
  

This is only a conceptual example. Production TLS configuration should follow current security guidance for the specific server and environment.

HTTPS for Bloggers and Website Owners

If you run a blog, portfolio, business website, or application, HTTPS should be treated as a basic security requirement.

Before publishing a website, check:

  • The site loads using HTTPS.
  • The certificate is valid.
  • Important pages do not expose sensitive data over HTTP.
  • Authentication cookies use appropriate security attributes.
  • Mixed-content issues are resolved.

What Is Mixed Content?

Mixed content occurs when an HTTPS page tries to load some resources using HTTP.

For example:

HTTPS page
   |
   +-- HTTPS image  ✓
   +-- HTTPS CSS    ✓
   +-- HTTP script  ✗
  

Modern browsers may block or restrict insecure resources because loading them over an unprotected connection can weaken the security of an HTTPS page.

HTTP/2 and HTTP/3

HTTPS should also be distinguished from HTTP versions.

HTTP/1.1, HTTP/2, and HTTP/3 are versions of the HTTP protocol or related transport architecture.

HTTPS describes the use of HTTP through a secure TLS-protected connection. HTTP/3 uses QUIC as its transport and incorporates TLS security as part of the protocol design.

Therefore:

HTTP vs HTTPS
     =
Security / transport protection concept

HTTP/1.1 vs HTTP/2 vs HTTP/3
     =
HTTP protocol versions
  

Frequently Asked Questions

```

What is the difference between HTTP and HTTPS?

HTTP is the standard web communication protocol, while HTTPS is HTTP carried over a TLS-protected connection that provides encryption, integrity protection, and server authentication.

What does HTTPS stand for?

HTTPS stands for Hypertext Transfer Protocol Secure.

What does HTTP stand for?

HTTP stands for Hypertext Transfer Protocol.

What port does HTTP use?

HTTP is conventionally associated with TCP port 80.

What port does HTTPS use?

HTTPS is conventionally associated with TCP port 443.

Is HTTPS encrypted?

Yes. HTTPS uses TLS to encrypt and protect application data sent through the secure connection.

What is SSL?

SSL stands for Secure Sockets Layer. It is an older security protocol that has been replaced by TLS. The term "SSL certificate" remains common in everyday usage.

What is TLS?

TLS stands for Transport Layer Security. It is the cryptographic protocol used by modern HTTPS connections.

Does HTTPS prevent hacking?

No. HTTPS protects data in transit but does not eliminate application vulnerabilities, compromised accounts, insecure configurations, or other security risks.

Can HTTPS protect passwords?

HTTPS helps protect passwords while they are transmitted between the browser or application and the server. The application must still securely store and process passwords.

Does HTTPS make a website trustworthy?

No. HTTPS helps authenticate the website's domain through the certificate system, but it does not guarantee the trustworthiness of the site's content, owner, products, or services.

What is an HTTPS certificate?

A TLS certificate is a digital certificate used as part of the HTTPS trust and authentication process.

```

Final Thoughts

The difference between HTTP and HTTPS is more than one extra letter in a website address.

HTTP provides the basic mechanism for transferring web resources, while HTTPS adds TLS protection to the communication channel.

HTTPS helps provide three important security properties: confidentiality, integrity, and server authentication.

For modern website owners, developers, and cybersecurity learners, understanding HTTPS is essential because secure transport is a fundamental layer of web security.

CodeWithAV Security Reminder:

Use HTTPS for websites and APIs, protect authentication credentials, validate certificates, configure secure cookies, remove mixed content, and remember that transport security is only one part of overall application security.

Related Articles on CodeWithAV

What Is JSON? Complete Beginner Guide

REST API Explained With Examples

What Is the Internet and How Does It Work?

How a Website Works From Browser to Server

Explore More Cybersecurity and Web Development Guides

Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

CodeWithAV — Learn, Discover & Build.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.