The DNS message format (RFC 1035): the 12-byte header and the resource record shape used for everything after it.
A resolver asking for example.com's A record, recursion desired. Every DNS message - query or response, over UDP or TCP - opens with exactly this 12-byte shape.
The first flags byte hasn't moved in almost 40 years. The second byte's 3-bit "must be zero" reserved field is where DNSSEC later carved out two new bits without touching the wire format at all.
No length field for the whole name and no separator bytes - each label is prefixed by its own length, and the name ends at a zero-length label (the DNS root). "example.com" is really two labels: 7-byte "example", then 3-byte "com".
Instead of repeating "example.com" again, this answer's NAME field points back at byte offset 12 - exactly where the QNAME started in the Question tab - and reuses it verbatim.
EDNS0 doesn't change the 12-byte header at all - it's a pseudo resource record dropped into the additional section, repurposing an RR's CLASS and TTL fields to carry a larger UDP payload size and extra header bits instead of the class/lifetime they'd normally mean.
The 12-byte header and the label/RR shapes above have outlived every one of these revisions - each addition either reused reserved bits or rode along as an additional pseudo-record, never forcing a wire-format break.
| era | addition | how it fit without breaking the header |
|---|---|---|
| 1987 | RFC 1035 - names, header, resource records | the baseline this whole page diagrams |
| 1996 | RFC 1996 - NOTIFY, for zone-transfer triggering | new opcode value (4) in the existing 4-bit Opcode field |
| 1999 | RFC 2535 - DNSSEC signatures; RFC 2671 - EDNS0 | AD/CD claimed from the reserved Z bits; EDNS0 added as an OPT pseudo-RR, see the EDNS0 tab |
| 2005 | RFC 4033-4035 - DNSSEC redesigned (NSEC, RRSIG, DNSKEY) | new RR types only - no header or flag changes needed |
| 2016 | RFC 7858 - DNS over TLS (DoT), port 853 | same message format, just a TLS-wrapped TCP socket instead of plain UDP/TCP 53 |
| 2018 | RFC 8484 - DNS over HTTPS (DoH) | same message format again, carried as the body of an HTTP request/response |