Front | Info | Lists | Newsfeeds | Study Guide | What is BSD?
Advertisement: The OpenBSD PF Packet Filter Book: PF for NetBSD, FreeBSD, DragonFly and OpenBSD

BSD Links
·New Links
·User Groups

This is the BSDA Study Guide Book written via a wiki collaboration. This is a work in progress. You may contribute to or discuss this specific page at

Understand various "domain" contexts

Author: Ivan Voras IvanVoras FreeBSD


The term "domain" is used in Unix for several facilities. Understand the meaning of the term in the context of the Network Information System (NIS), the Domain Name System (DNS), Kerberos, and NTLM domains.

TODO: should this briefly mention the UNIX-domain protocol for local (on-machine) interprocess communication (because it is also called "domain")?


All "domains" that we're dealing with here are different ways of grouping certain types of information together. In particular:

  • NIS, Kerberos and NTLM domains deal with system management and security - each of these allows managing system users and groups from a central location / repository that's located on dedicated servers. Machines belonging to one of these domains query the central server for security clearance and user information.
  • DNS is is a system that assignes human readable names to IP addresses. DNS names form a hierarchy in which each system's fully qualified domain name (FQDN) is formed from the domain name part and a single system name part, and the domain names can be nested.


DNS name are hierarchical and nested; thus the name:

refers to a machine called "www" in the domain "" which is nested in "" which is itself nested under ".com". The nslookup tool can be used to inspect DNS names:

> nslookup
Server:  dns.server.local

Non-authoritative answer:

Note that high traffic sites have multiple computers answering to the same DNS name, in order to help performance (as demonstrated in the above example). DNS databases actually contain several types of records. The most common are "A" records which are widely used to access generic resources, but arguably equally popular are "MX" records that hold addresses of e-mail servers for specific domains:

> nslookup
Default server: dns.server.local

> set type=mx
Non-authoritative answer:   preference = 50, mail exchanger =   preference = 5, mail exchanger =   preference = 10, mail exchanger =   preference = 10, mail exchanger =   preference = 50, mail exchanger =

Authoritative answers can be found from:   nameserver =   nameserver =   nameserver =   nameserver =

A Windows NT domain (NTLM) name is formed by two backlashes followed by a case-insensitive name containing no spaces, for example:


Computers and users on the NTLM domain can be referenced either by appending a backslash and the username to the domain name or by using the (misused in this case) standard unix notation user@domain:

TODO: I don't understand this "misused".


Practice Exercises

  1. Try several lookups of with nslookup and compare results
  2. See how many mail servers has

More information

domainname(1), resolv.conf(5), krb5.conf(5), smb.conf(5)

Front | Information | Lists | Newsfeeds