What's happening?
- DNS: the browser asks a resolver, which asks a root server, then the .org servers, then the domain's own nameserver for its IP address.
- TCP opens a connection to that IP; TLS proves the server's identity with a certificate and sets up encryption.
- HTTP asks for the page; the HTML leads to more requests for CSS, JavaScript and images, and then the page is drawn.
Where you'll meet it
This is the classic interview question, and the reason CDNs, DNS caching, keep-alive connections and TLS 1.3 exist: most of the wait is round trips.
Common mistake
Thinking DNS is one lookup at "the DNS server". It is a chain of servers — and every answer is cached for its TTL, which is why DNS changes take time to spread.
FAQ
What does a DNS resolver do?
It does the lookup on your behalf — asking root, top-level-domain and authoritative servers in turn — and caches the answer.
Why is a repeat visit faster?
The IP address is cached, so DNS is skipped, and the browser usually has CSS, JavaScript and images cached too.
What does HTTPS add?
A TLS handshake: the server proves who it is with a certificate, and both sides agree a key so nobody in between can read or change the traffic.
Are these times real?
They are typical round-trip times for illustration. Real ones depend on distance, network and caching.