
How does a website work? Your browser looks up the domain's IP address in DNS, opens a TCP connection to the server, negotiates encryption with TLS for HTTPS, sends an HTTP request and gets back a status code plus HTML. It then fetches the CSS, scripts and images that HTML references and draws the page.
That is the whole journey in one sentence. The rest of this guide walks through it the way a sysadmin would: what happens at each step, which error the browser shows when that step fails, and the command that lets you check it yourself. Knowing where the chain broke tells you who to contact — the domain registrar, the host, the developer or your own network.
How does a website work step by step?
A website is a set of files and programs on a server — a computer that is always online and answers requests. Your browser is the client. It knows nothing about the site until it asks, and it can only ask a numeric IP address, not a name. Everything you see on screen is assembled by the browser from the server's responses.
| Step | What happens | Typical browser error | How to check |
|---|---|---|---|
| 1. Parse the URL | Scheme, host and path are split out; HSTS is checked | A search page instead of the site (typo) | Address bar, DevTools |
| 2. DNS lookup | The domain name becomes an IP address | DNS_PROBE_FINISHED_NXDOMAIN, ERR_NAME_NOT_RESOLVED | nslookup, dig, /dns |
| 3. TCP connection | Three-way handshake on port 443 or 80 | ERR_CONNECTION_REFUSED, ERR_CONNECTION_TIMED_OUT | Test-NetConnection, nc, /traceroute |
| 4. TLS handshake | Certificate is verified, keys are agreed | NET::ERR_CERT_DATE_INVALID, NET::ERR_CERT_COMMON_NAME_INVALID | openssl s_client, /ssl |
| 5. HTTP request | Request with headers, response with a status code | 403, 404, 500, 502, 503, 504; ERR_TOO_MANY_REDIRECTS | curl -v, HTTP headers, /redirects |
| 6. Rendering | HTML parsed, CSS/JS/images fetched, page painted | Blank page, broken layout, console errors | DevTools Console and Network, /speed |
| 7. CDN and cache | A nearby edge node or the browser cache answers | Stale content, Cloudflare 52x errors | Age and Cache-Control headers |
What happens when you type a URL into the browser
The URL https://example.com/shop?page=2 breaks into a scheme (https), a host (example.com), a path (/shop) and a query string. If the site previously sent a Strict-Transport-Security header, or is on the browser's HSTS preload list, the browser will never try plain HTTP: in DevTools you see an internal 307 redirect to HTTPS before any network traffic. If what you typed doesn't look like an address, it goes to the search engine instead — the first place where "the site is down" is really a typo.
How DNS turns a domain name into an IP address
The browser checks its own cache, then the operating system's cache and the hosts file (C:\Windows\System32\drivers\etc\hosts on Windows, /etc/hosts on Linux and macOS). If there is no answer, the query goes to a recursive resolver — your ISP's, your router's, or a public one such as 1.1.1.1 or 8.8.8.8.
If the resolver has nothing cached, it walks the hierarchy: a root server points to the servers for the top-level domain (.com), those point to the domain's authoritative name servers, and the authoritative server returns an A record (IPv4) or AAAA record (IPv6). The resolver caches each answer for the record's TTL, in seconds. That is why, after you move a site to a new IP, some visitors keep reaching the old server until their resolver's copy expires. For the full picture, see what DNS is and how it works.
# Windows (cmd or PowerShell)
nslookup example.com
nslookup example.com 8.8.8.8
Resolve-DnsName example.com -Type A
# Linux / macOS
dig example.com A +short
dig example.com @1.1.1.1
dig +trace example.com
In dig output, look at status in the header: NOERROR means the name exists, NXDOMAIN means it doesn't, SERVFAIL means the resolver couldn't get an answer (broken DNSSEC and unreachable name servers are common causes). dig +trace does the walk from the root itself and shows where it stops. Asking a specific resolver lets you tell a stale local cache from a real problem. To see a domain's records from outside your network, use the DNS lookup.
How the client and server connect
With an IP address in hand, the browser opens a TCP connection: the client sends SYN, the server replies SYN-ACK, the client answers ACK. HTTPS uses port 443, plain HTTP port 80. This is the client-server model at its simplest — the client always starts the conversation; the server listens on a port and replies.
- ERR_CONNECTION_REFUSED — the host is reachable, but nothing is listening on the port, so it actively rejects the connection.
- ERR_CONNECTION_TIMED_OUT — no reply at all: packets are dropped by a firewall, lost on the way, or the server is off.
- ERR_CONNECTION_RESET — the connection was cut mid-way by the server, a load balancer or something in between.
# Windows PowerShell
Test-NetConnection example.com -Port 443
# Linux / macOS
nc -vz example.com 443
# The route to the server
tracert example.com # Windows
traceroute example.com # Linux / macOS
mtr -rw example.com # per-hop report
TcpTestSucceeded : True in the PowerShell output means the port is open. Don't rely on ping alone: plenty of servers and networks drop ICMP, so a silent ping doesn't prove the site is down. The traceroute tool shows where the route stops from the outside.
How HTTPS works: the TLS handshake
For an https address, TLS runs on top of TCP. The browser lists the protocol versions and cipher suites it supports and sends the site name in the SNI extension, so a server hosting hundreds of domains knows which certificate to present. The server sends its certificate and intermediate chain, both sides derive a shared key, and everything after that is encrypted. TLS 1.3 needs one round trip for the handshake, TLS 1.2 needs two. The message-by-message flow is covered in the TLS handshake explained, and the protocol itself in RFC 8446.
The browser checks three things: the certificate hasn't expired, the name on it matches the domain, and the chain leads to a root the device trusts. Each failure has its own error — NET::ERR_CERT_DATE_INVALID (expired, or the device clock is wrong), NET::ERR_CERT_COMMON_NAME_INVALID (issued for example.com but you opened www.example.com), NET::ERR_CERT_AUTHORITY_INVALID (self-signed, incomplete chain or an untrusted root).
openssl s_client -connect example.com:443 -servername example.com </dev/null
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null \
| openssl x509 -noout -subject -issuer -dates
Look for Verify return code: 0 (ok) near the end of the first command's output. Always pass -servername: on shared servers you may otherwise get a neighbouring site's certificate. The SSL checker shows the certificate, chain and expiry date from outside.
What the web server does with the request
Once the channel is ready, the browser sends an HTTP request. In HTTP/1.1 it is plain text:
GET /shop?page=2 HTTP/1.1
Host: example.com
User-Agent: Mozilla/5.0 ...
Accept: text/html
Accept-Encoding: gzip, br
Cookie: session=...
The Host header tells the server which of the sites on that IP you want. A web server such as nginx or Apache receives the request. Static files — images, CSS — it serves straight from disk. Dynamic pages go to an application (PHP-FPM, Node.js, Python), which reads the database, builds HTML and hands it back. Often a reverse proxy or load balancer sits in front and spreads requests across several servers.
The response starts with a status line, then headers, then the body. The status code is the first thing to read when something fails: 2xx success, 3xx redirect (target in Location), 4xx a problem with the request (403 forbidden, 404 not found), 5xx a server-side failure (500 application error, 502 and 504 the proxy got no proper answer from the application, 503 temporarily unavailable). The full list is in the HTTP status codes reference, and what each header does is in HTTP headers explained. HTTP semantics are defined in RFC 9110.
curl -v https://example.com/ -o /dev/null
curl -I https://example.com/
curl -sL -o /dev/null -w "%{http_code} %{url_effective}\n" http://example.com/
In curl -v output, lines starting with * are connection and TLS details, > is what the client sent, < is what the server returned. The last command follows every redirect and prints the final code and URL — handy when the browser reports ERR_TOO_MANY_REDIRECTS. On Windows 10 and 11 call curl.exe, because in Windows PowerShell 5.1 curl is an alias for a different cmdlet. From outside, the HTTP header checker and redirect checker show the same exchange.
HTTP itself is stateless: each request stands alone. Logins survive between pages because the server sends Set-Cookie and the browser returns the value in a Cookie header on every later request.
How the browser turns code into a page
The browser parses the HTML into a DOM tree and, as it meets links to stylesheets, scripts and images, requests each one — often dozens of extra requests, some to other domains (fonts, analytics, CDNs), each repeating DNS, TCP and TLS. HTTP/2 and HTTP/3 carry many files over one connection in parallel. CSS becomes a style model; together with the DOM it produces the render tree, then layout and paint. A plain <script> without async or defer pauses HTML parsing until it downloads and runs.
Failures here are invisible to the server — it returned 200, yet the user sees a blank page. Press F12: the Console tab lists JavaScript errors, the Network tab shows which files failed and with what code. The speed test measures load and render time. To split server response time into phases:
curl -o /dev/null -s -w "dns %{time_namelookup}\ntcp %{time_connect}\ntls %{time_appconnect}\nttfb %{time_starttransfer}\ntotal %{time_total}\n" https://example.com/
The values are cumulative seconds from the start. A big gap between tls and ttfb means the application or database is slow, not the network.
CDNs and caching
Many sites sit behind a CDN, a network of servers close to users. DNS points to an edge node, which serves a cached copy or fetches the page from the origin server. The browser keeps its own copy if Cache-Control allows it. Two problems follow. Visitors may see an old version after a release; the Age header shows how many seconds a response has been cached, and Cloudflare adds CF-Cache-Status with HIT or MISS. Or the CDN is fine but the origin isn't, and the CDN draws its own error page — Cloudflare's 521 (origin refused the connection), 522 (origin timed out) and 525 (TLS handshake with the origin failed).
Static vs dynamic websites
| Static site | Dynamic site | |
|---|---|---|
| What the server returns | Ready-made HTML files | HTML built by an application per request |
| Moving parts | Web server or CDN | Web server, application, database, often a cache |
| Typical failures | DNS, certificate, 404 after a move | All of those plus 500, 502, 504, slow queries |
| Examples | Landing page, docs | Online store, account area, CMS |
Which kind you run shapes what hosting you need; the basics are in what web hosting is.
How to check which step is failing
- Does the name resolve?
nslookup example.com 8.8.8.8, or the DNS lookup. - Is the port open?
Test-NetConnection example.com -Port 443ornc -vz example.com 443. - Is the certificate valid?
openssl s_clientwith-servername, or the SSL checker. - What status code comes back?
curl -I, or the HTTP header checker. For 5xx, read the web server and application logs. - Status 200 but an empty page? DevTools, Console and Network tabs.
If the site fails only from your machine while outside checks pass, the problem is local: DNS cache, hosts file, a browser extension, your ISP or a corporate firewall.
Frequently asked questions
How much does a website cost?
The recurring parts are the domain (renewed yearly with a registrar), hosting (monthly or yearly) and a TLS certificate, which is free from Let's Encrypt and many hosts. Development is the variable part: a builder template costs almost nothing, a custom store with a database costs far more to build and maintain.
Can anyone just create a website?
Yes. Register a domain, rent hosting or use a site builder, point the domain's A record or name servers at it, and enable HTTPS. The builder hides steps 2–5 above, but they still happen on every visit.
Why does a site load for me but not for others?
Usually DNS caching after an IP change: your resolver already has the new address, theirs still holds the old one until the TTL runs out. Compare answers from different resolvers with nslookup name 8.8.8.8 and nslookup name 1.1.1.1.
Is ping enough to tell whether a website is up?
No. Ping only shows that a host answers ICMP. The web server on port 443 can be stopped while ping works, and many servers block ping while the site is fine. Test the port and the HTTP status instead.
What is the difference between a website and a web server?
The web server is the software (nginx, Apache) and the machine it runs on; the website is the content and application it serves. One server can host many websites, told apart by the Host header and SNI.