How Resolution Works
What happens between a name lookup arriving and its answer, and what a refusal looks like on the wire.
On this page (5)
How Resolution Works Documentation
A lookup arrives on one of two channels: over encrypted DNS with a credential, or on plain port 53 at the resolver address your account was given, where the source address is the credential. Both channels reach the same resolver and get the same answer.
The graph is asked first
Before any recursion happens, the resolver asks the Whisper graph for a verdict on the name. The verdict carries a severity band and a statement of what was actually looked at, which is the vocabulary set out in Coverage.
The bands decide the outcome. The top bands are sinkholed. The middle band resolves and is recorded. The low bands resolve. A name the graph has never observed has no verdict at all, and falls through to your account's default action.
What each outcome looks like
An allow is an ordinary answer, indistinguishable on the wire from any other resolver's.
A block is either NXDOMAIN or a fixed sinkhole address, depending on how your account is set up, so a client gets a clean failure rather than a hang.
No opinion means the resolver continues with ordinary recursive resolution and returns what the authoritative servers say.
When the graph is slow
The resolver does not hold a lookup open waiting for a verdict. If the graph has not
answered in time, resolution proceeds. The one exception is the graph-only mode, which
answers only from the graph and returns REFUSED with extended DNS error 17 when it has
nothing to say. Modes are on Resolver Policy.
Answers from the policy resolver do not carry the AD bit. When you need DNSSEC proof for an identity check, validate it yourself against the signed zone, as Verify an Identity shows.
Your policy narrows, it does not widen
Account policy can tighten a verdict and cannot loosen one. A name on your allow list still does not resolve if the graph puts it in a top band, which means an operator mistake cannot turn a known-bad name back on.
Reading what happened
Every lookup is recorded with the name, the type, the response code, the decision and the reason behind it. That is the record to reach for when somebody reports that something stopped working:
whisper logs --agent checkout-bot --from -1h --kind dns | jq '.[] | select(.decision=="blocked")'
The same rows are on the control plane through Read Query Logs, and the field list lives there.