Skip to content
Skip to main content
IP Addresses & Networks Technical Explainer

Does a DNS query prove that somebody visited a website?

A DNS query shows that a device or network asked for information about a domain. It is useful evidence of interest or system activity, but the next question is what caused it and what followed.

Why the query may exist

A person may have typed an address or clicked a link. Queries can also be generated by:

  • browser prefetching;
  • advertising, analytics, images or fonts loaded by another page;
  • apps and background services;
  • email previews and automated link scanners;
  • security software; and
  • operating-system updates or connectivity checks.

For example, Dave receives an email containing an image hosted at news.example. His mail application previews the message and looks up that domain before he opens a browser. The DNS record is genuine, but the cause is automated content loading rather than a deliberate website visit.

Build the conclusion from joined records

Evidence available What it can support What remains open
DNS query for news.example The logging system received a request for information about the name Which application or process caused it
DNS query plus connection to the returned address A related connection may have followed Whether the traffic was a web page, embedded content or another service
Proxy, browser or application record naming news.example The named application or service handled the event What a person saw or intended, unless the record captures that context
Service-side session or account event The service recorded a corresponding activity Who controlled the account or device at the time

The evidence becomes more specific as independent records join the name lookup to a connection, application and service event. Compare timestamps, device or client identifiers and session context before treating them as one chain.

What to do next

Use the DNS query log as the starting point and look for activity around the same time:

  • a connection to an address returned by DNS;
  • a hostname, URL or SNI value in network records;
  • browser history or cached content;
  • proxy or application logs;
  • account activity; or
  • access records held by the service.

Also identify where the DNS record was created. A local resolver may identify the requesting device, while an authoritative server may show only the public resolver that asked the question.

If there is no DNS query

The device may have used a cached answer, another resolver, encrypted DNS, a VPN, a local configuration or the IP address directly. Check the other available records before treating the absence as significant.

A useful way to describe it

The query supports the conclusion that the device or network sought DNS information about the domain at the recorded time. The surrounding records can then show whether a connection followed and what the user or application did.

Operational takeaway

A DNS query is useful evidence of a name lookup, not proof of a website visit. Identify the process or device that caused it, then join it to connection, application and service records.

Explore related guidance
Reference: IP-044IP Addresses & Networks