10 · Email + DNS
Slides 2-48 → 2-69 · HW2 P4
Part 1 · Email
Three components
| Component | What it is |
|---|---|
| User agent ("mail reader") | Composes, edits and reads mail. E.g. Outlook, iPhone Mail |
| Mail server | Holds a mailbox (incoming messages for the user) and a message queue (outgoing messages waiting to be sent) |
| SMTP | The protocol mail servers use to send email to each other |
SMTP (RFC 5321)
- Uses TCP, port 25, to reliably transfer email.
- Direct transfer: the sending server (acting as the client) connects straight to the receiving server (the server).
- Three phases: handshaking (greeting) → transfer of messages → closure.
- Command/response, like HTTP: commands are ASCII text, responses are a status code + phrase.
Alice sends email to Bob (6 steps)
- Alice uses her user agent to write a message to bob@someschool.edu.
- Her UA sends it to her mail server, where it goes in the message queue.
- The client side of SMTP on her server opens a TCP connection to Bob's mail server.
- The SMTP client sends Alice's message over that connection.
- Bob's mail server puts it in Bob's mailbox.
- Bob uses his user agent to read it.
Notice: Alice's UA → her server is one hop, and her server → Bob's server is another. The message is never sent straight from Alice's computer to Bob's.
Sample SMTP interaction
S: 220 hamburger.edu C: HELO crepes.fr S: 250 Hello crepes.fr, pleased to meet you C: MAIL FROM: <alice@crepes.fr> S: 250 alice@crepes.fr... Sender ok C: RCPT TO: <bob@hamburger.edu> S: 250 bob@hamburger.edu ... Recipient ok C: DATA S: 354 Enter mail, end with "." on a line by itself C: Do you like ketchup? C: How about pickles? C: . ← end of message S: 250 Message accepted for delivery C: QUIT S: 221 hamburger.edu closing connection
SMTP vs HTTP
| HTTP | SMTP | |
|---|---|---|
| Direction | Pull (client pulls objects from the server) | Push (sending server pushes mail to the receiving server) |
| Both | ASCII command/response interaction and status codes | |
| Multiple objects | Each object in its own response message | Multiple objects in one multipart message |
| Connections | Persistent or non-persistent | Persistent |
| Data | Any data, including binary | Header and body must be 7-bit ASCII |
| End of message | Content-Length: header | A line with only a period: CRLF.CRLF |
Worked example: HW2 P4
Q: How does SMTP mark the end of a message body? How about HTTP? Can HTTP use the same method as SMTP?
- SMTP: a line containing only a period (
CRLF.CRLF). - HTTP: the
Content-Length:header field gives the length of the body. - No, HTTP can't use SMTP's method. An HTTP body can contain arbitrary binary data (images, video…), which could contain the CRLF.CRLF byte pattern by accident and end the message early. SMTP gets away with it because it only carries 7-bit ASCII.
Mail message format (RFC 822)
- SMTP is the protocol for exchanging messages (like HTTP). RFC 822 defines the syntax of the message itself (like HTML).
- Header lines (
To:,From:,Subject:), then a blank line, then the body (ASCII only). - These header lines are not the same as the SMTP commands
MAIL FROM:andRCPT TO:. Those are part of the SMTP conversation; the headers are inside the message.
Mail access protocols
- SMTP only handles delivery to (and storage on) the receiver's server. It's a push protocol, so the receiver can't use it to pull mail down.
- A mail access protocol retrieves mail from the server:
- IMAP (Internet Mail Access Protocol): messages stay stored on the server. IMAP gives retrieval, deletion, and folders.
- HTTP: webmail (Gmail, Hotmail, Yahoo! Mail) gives a Web interface, using SMTP to send and IMAP (or POP) to retrieve behind the scenes.
Full path: Alice's UA →SMTP→ Alice's server →SMTP→ Bob's server →IMAP/HTTP→ Bob's UA.
Part 2 · DNS
What DNS is
- Hosts have IP addresses (32 bits, used to address datagrams) and names (e.g. cs.umass.edu, used by humans). DNS maps between them.
- Domain Name System = a distributed database implemented in a hierarchy of many name servers.
- It's an application-layer protocol, even though it's a core Internet function. That keeps the complexity at the network's edge.
- DNS queries normally go over UDP (that's why HW2 P1 says "UDP for DNS").
DNS services
- Hostname → IP address translation
- Host aliasing: an alias name maps to the real ("canonical") name
- Mail server aliasing
- Load distribution: replicated Web servers, so many IP addresses map to one name
Why not one central DNS server?
It doesn't scale:
- Single point of failure
- Traffic volume (Comcast's DNS servers alone handle 600 billion queries a day)
- Distant centralized database (far away for most users)
- Maintenance
The hierarchy
| Level | What it does | Examples |
|---|---|---|
| Root | Contact of last resort for servers that can't resolve a name. Points you to the TLD server. 13 logical root servers, each replicated many times. Managed by ICANN. | |
| Top-Level Domain (TLD) | Responsible for one top-level domain. Points you to the authoritative server. | .com, .org, .net, .edu, country domains (.uk, .fr, .jp…). Network Solutions runs .com/.net, Educause runs .edu |
| Authoritative | An organization's own DNS server, with the official hostname → IP mappings for its hosts. Run by the org or a service provider. | amazon.com DNS servers, umass.edu DNS servers |
To find www.amazon.com: ask root → get the .com TLD server. Ask .com → get the amazon.com authoritative server. Ask that → get the IP address.
Local DNS server
- Not strictly part of the hierarchy. Every ISP (residential, company, university) has one. Also called the default name server.
- Your host sends every DNS query to its local DNS server first.
- It has a cache of recent translations (which may be out of date), and acts as a proxy that forwards the query into the hierarchy.
Iterated vs recursive queries
Example: a host at engineering.nyu.edu wants the IP of gaia.cs.umass.edu. Local server = dns.nyu.edu, authoritative = dns.cs.umass.edu.
| Iterated | Recursive |
|---|---|
| Each contacted server replies with the name of the next server to ask: "I don't know this name, but ask this server." | Each contacted server takes on the job itself and asks the next server on your behalf. |
| The local DNS server does all the asking: host → local, then local → root, local → TLD, local → authoritative, then local → host. | The query chains down: host → local → root → TLD → authoritative, then the answer travels back up the same chain. |
| 8 messages | 8 messages |
| Light load on root/TLD | Puts the burden on the contacted servers → heavy load at upper levels of the hierarchy |
Usually: the host → local query is recursive ("just get me the answer"), and local → everyone else is iterated.
Ties to topic 8: in HW2 P0, "n DNS servers visited, RTT₁…RTTₙ" is this lookup. Each visit costs one RTT.
Ties to topic 8: in HW2 P0, "n DNS servers visited, RTT₁…RTTₙ" is this lookup. Each visit costs one RTT.
Caching
- Once any name server learns a mapping, it caches it.
- Cache entries time out after their TTL (time to live).
- TLD server addresses are usually cached in local servers, so root servers aren't visited often.
- Cached entries can be out of date (DNS is best-effort). If a host changes its IP, the Internet may not know until every TTL expires.
DNS records
The database stores resource records (RR) in the format (name, value, type, ttl).
| Type | name | value |
|---|---|---|
| A | hostname | IP address |
| NS | domain (e.g. foo.com) | hostname of the authoritative name server for that domain |
| CNAME | alias name | canonical (real) name. E.g. www.ibm.com is really servereast.backup2.ibm.com |
| MX | name | name of the mail server for that name |
Memory hook: A = Address. NS = Name Server. CNAME = Canonical NAME. MX = Mail eXchange.
DNS messages
Query and reply use the same format. Header:
- Identification: a 16-bit number for the query. The reply uses the same number, so the host can match them.
- Flags: query or reply, recursion desired, recursion available, reply is authoritative.
- Counts, then 4 sections: questions (name, type), answers (RRs answering the query), authority (records for authoritative servers), additional info (extra helpful records).
Inserting records: new startup "Network Utopia"
- Register networkutopia.com at a DNS registrar (e.g. Network Solutions). Give it the names and IPs of your authoritative name servers (primary and secondary).
- The registrar inserts an NS and an A record into the .com TLD server:
(networkutopia.com, dns1.networkutopia.com, NS)
(dns1.networkutopia.com, 212.212.212.1, A) - Set up the authoritative server at 212.212.212.1 with an A record for www.networkutopia.com and an MX record for networkutopia.com.
DNS security
| Attack | What happens |
|---|---|
| DDoS on root servers | Not successful so far: traffic filtering, and local servers cache TLD IPs, so root servers can be bypassed |
| DDoS on TLD servers | Potentially more dangerous |
| Spoofing | Intercept DNS queries and return bogus replies (DNS cache poisoning). Defense: DNSSEC (authentication, RFC 4033) |
Quick check
1. How does SMTP mark the end of a message body? HTTP? Can HTTP use SMTP's method? (HW2 P4)
SMTP: a line with only a period (CRLF.CRLF). HTTP: theContent-Length header. No: an HTTP body can be arbitrary binary data, which might contain CRLF.CRLF by accident. SMTP only carries 7-bit ASCII.2. Name the three main components of email.
User agents, mail servers, and SMTP.3. Is SMTP push or pull? HTTP?
SMTP = push. HTTP = pull.4. Why does Bob need IMAP (or HTTP) to read his mail? Why not SMTP?
SMTP is a push protocol for delivering mail to a server. Bob needs to pull mail from his server, which is what a mail access protocol (IMAP, or HTTP for webmail) does.5. Which transport protocol and port does SMTP use?
TCP, port 25.6. Give 3 reasons DNS isn't centralized.
Any three: single point of failure, huge traffic volume, distant database (slow for most users), maintenance. In short: it doesn't scale.7. Name the 3 levels of the DNS hierarchy, top to bottom. Where does the local DNS server fit?
Root → TLD → authoritative. The local DNS server isn't strictly part of the hierarchy: it's the ISP's default server that takes the host's query and forwards it in.8. Iterated vs recursive: which one puts heavy load on the root and TLD servers?
Recursive, because each contacted server has to resolve the rest of the name itself. In iterated queries, each server just says "ask this server next".9. Which record type: (a) hostname → IP? (b) alias → real name? (c) domain → its name server? (d) domain → its mail server?
(a) A (b) CNAME (c) NS (d) MX10. Why are root servers not visited often?
Local DNS servers cache TLD server addresses, so most queries skip the root.11. A website changes its IP address. Why might some users still reach the old one?
Their DNS servers still have the old mapping cached. It won't update until the cache entry's TTL expires.Next: P2P file distribution and BitTorrent, a big calculation topic (HW2 P5–P7, sample P6).