The model
DNS maps names to typed records through a distributed hierarchy. A stub resolver usually asks a recursive resolver to find an answer. That resolver may consult caches, follow referrals from root to top-level and authoritative servers, and return records with a time-to-live.
A concrete walk-through
For a hostname, the answer can involve a CNAME alias followed by address records. The recursive resolver caches each record within its TTL, so two clients can observe different answers during a change. Negative answers can also be cached, affecting how quickly a newly created name becomes visible.
Costs and failure cases
DNS is not a single global database lookup and a resolver’s cache may be stale until expiration. Multiple A or AAAA records do not guarantee that every client uses them as intended. DNSSEC can authenticate signed DNS data, but it does not encrypt ordinary DNS queries or secure the application protocol.
Check your understanding
A service moves to a new address but some users keep reaching the old one. Trace which caches may be involved and explain why lowering TTL immediately before a change may not help clients that cached an earlier TTL.