Skip to content
Skip to main content
IP Addresses & Networks Technical Explainer

Why can one domain name resolve to several IP addresses?

One domain name can return several IP addresses. This is normal and is often how a large or resilient online service is designed.

Common reasons

Sharing the demand

A service can use several servers and spread connections between them. Its A and AAAA records may contain several addresses, and the order can change between queries.

Keeping the service available

If one server or data centre has a problem, users can be directed to working infrastructure elsewhere.

Using a content-delivery network

A content-delivery network (CDN) operates delivery infrastructure in many locations, often closer to users than the website's origin server. The DNS answer may depend on the user's region, the resolver making the query or current network conditions.

Supporting IPv4 and IPv6

The same service may publish both IPv4 and IPv6 routes. They are different ways to reach the service, not necessarily different websites.

Anycast

With anycast, the same IP address can be announced from several locations. Even one returned address may therefore lead to different physical infrastructure depending on where the connection starts.

Compare the answer with the event

Dave looks up media.example from a mobile connection at 09:00. An investigator repeats the lookup from an office resolver two days later. Both results may be legitimate without being identical.

Observation Answer What the difference might mean
Mobile resolver, event time 198.51.100.40, 198.51.100.41 The service offered two IPv4 routes from that resolver's location
Device connection record 198.51.100.41:443 The device attempted the second returned route
Office resolver, two days later 203.0.113.70 Geography, service configuration, caching or later change may have produced a different answer

The connection record is the stronger evidence of the address actually used for that event. The later lookup helps explain the service's infrastructure, but it should not replace the event-time record.

What this means for the enquiry

Do not treat today's DNS answer as a complete history of the service. Save the original address from the event record and establish the relevant time.

If you are trying to link a recorded connection to a domain, useful sources may include:

  • DNS answers or query logs from the event time;
  • the hostname, URL or SNI value in the original record;
  • platform or server logs; and
  • historical DNS information.

The address actually used should come from the original device, network or platform record wherever possible.

Operational takeaway

Several answers are normal. Preserve all event-time answers, then identify the address actually used from the connection or application evidence. Do not substitute a later lookup for the original event.

Explore related guidance
Reference: IP-039IP Addresses & Networks