What actually happens when you type a web address?
A surprising amount, in well under a second. The sequence is one of the most useful things to understand about how the internet works.
1. The browser checks its caches. Browser cache, then the operating system cache, then the hosts file — if the address was resolved recently, it skips ahead.
2. DNS resolution. Computers route by IP address, not names, so example.com must be translated. Your device asks a resolver, usually run by your ISP or a public service like 1.1.1.1 or 8.8.8.8. If the resolver does not know, it asks a root server, which directs it to the top-level domain server for .com, which directs it to the authoritative nameserver for the domain, which returns the IP. Results are cached at every level, with a TTL controlling for how long — which is why DNS changes take time to propagate.
3. TCP connection. A three-way handshake — SYN, SYN-ACK, ACK — establishes a reliable channel to that IP on port 443.
4. TLS handshake. The server presents its certificate, the browser verifies it was issued by a trusted certificate authority and matches the domain, and the two agree encryption keys. This is what makes it HTTPS.
5. HTTP request. The browser sends GET / with headers including cookies and the user agent.
6. The server responds — often via a CDN edge server geographically near you rather than the origin — with a status code and HTML.
7. The browser renders. It parses HTML into a DOM, discovers references to CSS, JavaScript, images and fonts, and fetches each one, potentially repeating the whole process for other domains. It builds a render tree, calculates layout, and paints.
Where it typically goes wrong: DNS failures, expired certificates, and slow third-party resources are the most common causes.