DNS has grown into an enormously complex system
queue.acm.org
queue.acm.org
host -T www.google.comIt's also faster... Assuming everything works, it's one round trip time for the query and response for UDP, as opposed to 2 for the TCP case because you have to set up the connection first.
Being connectionless means that the server can be much more efficient, because it never has to keep track of any connections or state.
And, as others have pointed out, you just retransmit if you don't get an answer. TCP isn't really lossless, it just guarantees that you know when you've lost something which is an important distinction. And with DNS, that's pretty easy -- you didn't get your answer. TCP would take a while to figure this out, with UDP you can pick your timeout.
Also, TCP provides lossless transmission on lossy media by retransmitting packets, which is what DNS does anyway.
(For when the response would be more than one UDP packet, "reliability" would also include receiving the packets in order. In that case DNS would tell the user to do the request over TCP.)
TCP does reliability for you. UDP lets you implement whatever form of reliability you want in the application.
For DNS, you can do a much better job implementing DNS-specific forms of reliability. For example, if you have multiple nameservers, just move on to the next one instead of trying to retransmit packets to the first one that fails.
All duly upvoted, I wanted to express my gratitude collectively for all the explanations. HN is a true gem of the Internet.
Further, at the time DNS was designed, TCP was not considered 'scalable' since each TCP connection required its own file descriptor and computers at the time struggled with even 64 file descriptors per process. As DNS was not distributed at the zone level (it was replicated but each replica had the full zone contents of those zones they mirrored).
These days UDP is still faster for small packets but as others have pointed out DNS switches to TCP for bigger requests.
http://www.icann.org/en/announcements/factsheet-dns-attack-0...