DNS record

A single entry in a DNS Domain Name System The internet's directory that links domain names to computer addresses. Full definition of DNS zone. It has a name, a type such as A, MX or TXT, a TTL Time to Live How long resolvers may keep a saved copy of a DNS record. Full definition of TTL and the data itself, for example an IP Internet Protocol The internet's basic rules for sending data, using numeric addresses for every connected device. Full definition of IP. All records with the same name and type form a set that is always answered and signed together.

category
DNS and technical foundations

Updated on 5 min read

A DNS record is one entry in a domain’s DNS zone. Each record answers one question about a name, such as which server hosts the website or where email should go. Domain owners usually edit a few records through their DNS provider A company that runs the name servers for a domain, which may differ from the registrar. Full definition of DNS provider, and one wrong record can stop a website or email from working.

What a DNS record is: name, type, TTL and data

Every record has the same parts: the name it belongs to (such as www.example.com), a type (A, MX, TXT and so on), a TTL and the data itself, such as an IP address.

The TTL is the number of seconds a resolver The DNS server that looks up domain names on behalf of users. Full definition of resolver may keep the answer before asking again. It is a maximum, not a promise. After a change, some users keep seeing the old value until the old TTL runs out, which is what people informally call DNS propagation The delay before a DNS change is seen everywhere, caused by cached answers expiring. Full definition of DNS propagation.

Records with the same name and type form a resource record set (RRset). A query always returns the whole set, all its records must have the same TTL, and DNSSEC Domain Name System Security Extensions Digital signatures that prove DNS answers are genuine and unchanged. Full definition of DNSSEC signs the set as a unit.

The records most owners need: A, AAAA, CNAME, MX and TXT

  • A points a name to an address in Internet Protocol version 4 (IPv4). Several addresses mean several A record A DNS record that points a domain name to an IPv4 address. Full definition of A record.
  • AAAA does the same for the newer, longer version 6 (IPv6).
  • CNAME makes a name an alias of exactly one other name, and the lookup restarts there. No other data may sit at an alias, except DNSSEC records.
  • MX names a domain’s mail servers, each with a preference number; lower numbers are tried first. The target must be a real host name, never an alias. With no MX at all, sending servers fall back to the domain’s A or AAAA record A DNS record that points a domain name to an IPv6 address. Full definition of AAAA record. A domain that takes no mail can publish a “null MX”: preference 0 and a single dot as target.
  • TXT holds text whose meaning depends on where it is published. Services often ask for a TXT value to prove control of a domain. SPF Sender Policy Framework A DNS record listing the servers allowed to send email for a domain. Full definition of SPF must be published as TXT, with only one SPF record per name. A DMARC Domain-based Message Authentication, Reporting and Conformance A DNS-published policy telling mail receivers how to treat email that fails authentication. Full definition of DMARC is a TXT record Text record A DNS record holding text, often for domain verification and email security. Full definition of TXT record at _dmarc.example.com.

Records that run the zone: NS and SOA

NS record Name Server record A DNS record that lists the name servers responsible for a domain. Full definition of NS record list a zone’s authoritative name server A server that holds a domain's DNS records and answers lookups. Full definition of name server. They sit at the top of the zone and also in the parent zone, such as the TLD top-level domain The last part of a domain name, after the final dot. Full definition of TLD zone, where they mark the delegation and tell resolvers where to ask next. They must point to real host names, not aliases.

Each zone has exactly one SOA record Start of Authority The record at the top of a DNS zone holding its serial number and timing settings. Full definition of SOA record (start of authority) record, at the top. It holds the primary server, the responsible person’s mailbox, a serial number and timers in seconds. Secondary servers fetch new data only when the serial increases. Its MINIMUM field, with the SOA’s own TTL, now sets how long “does not exist” answers are cached. DNS providers usually manage the SOA for their customers.

Specialized records: SRV, PTR, CAA, HTTPS and wildcards

  • SRV record Service A DNS record giving the server and port for a specific service on a domain. Full definition of SRV record gives the server and port for a service, under a name such as _service._protocol.example.com. Clients try the lowest priority first and share load by weight. The target must not be an alias.
  • PTR record Pointer A DNS record that maps an IP address back to a hostname. Full definition of PTR record maps an address back to a name. Reverse records live under in-addr.arpa (IPv4) and ip6.arpa (IPv6), zones that follow the structure of IP addresses, not domain name A readable internet name made of labels separated by dots. Full definition of domain name, so they are not set in a domain’s own zone. Operational advice says PTR and A records should match.
  • CAA record Certification Authority Authorization A DNS record listing which certificate authorities may issue certificates for a domain. Full definition of CAA record (Certification Authority Authorization) lists the certification authorities that may issue certificates for a name. Authorities that follow the standard must check it before issuing, climbing to parent names if needed, so a CAA set at example.com also covers www.example.com if www has none. Browsers must not use it to validate certificates.
  • HTTPS and SVCB records DNS records that tell clients how to connect to a service, including websites. Full definition of HTTPS and SVCB records and HTTPS Hypertext Transfer Protocol Secure The encrypted version of the protocol web browsers use to load pages. Full definition of HTTPS tell clients, before they connect, which servers, protocols and ports to use. HTTPS is the web version; the name refers to the record type, not the protocol.
  • Wildcards start with the label One dot-separated part of a domain name, up to 63 characters long. Full definition of label *, as in *.example.com. They answer only for names that do not exist at all, only with the types they hold, and not for names below themselves. As of October 2026, ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN’s Registry Agreement The contract between ICANN and a gTLD registry operator. Full definition of Registry Agreement, approved on 21 January 2024, forbids gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry to use wildcards or any other method to answer for unregistered names: such queries must return NXDOMAIN Non-Existent Domain The DNS answer meaning the requested name does not exist. Full definition of NXDOMAIN.

Why a CNAME cannot sit at the bare domain, and ALIAS workarounds

The bare domain (the zone apex) must hold the SOA and NS records, and a CNAME cannot share its name with other data. A CNAME there conflicts with them: some servers then ignore the NS records, and the domain stops working.

The standard answer is A and AAAA records at the bare domain. An HTTPS record in “AliasMode” can also point the bare domain to another name, but clients that do not support it ignore it, so the A and AAAA records must stay.

Many DNS providers offer their own feature, called ALIAS, ALIAS record A provider-specific way to point a bare domain at another hostname. Full definition of ALIAS record or CNAME flattening: the provider looks up the target and answers with its addresses. As of October 2026 these features are proprietary. The draft to standardize ANAME expired, and IANA Internet Assigned Numbers Authority The functions that coordinate the root zone, IP addresses and protocol numbers. Full definition of IANA’s registry of record types has no ALIAS or ANAME type. Behavior differs, which makes changing provider or using several harder.

Common mistakes when editing records and how to check them

  • Leaving out the final dot of a full name in a zone file The set of all DNS records for a domain or TLD. Full definition of zone file, so the zone name is added: mail.example.com.example.com.
  • A CNAME next to other records, or at the bare domain.
  • An MX, NS or SRV record pointing to a CNAME.
  • Two SPF records at the same name.
  • Not raising the SOA serial when editing a zone file by hand.
  • CNAMEs left pointing to a removed host, or CNAMEs pointing to CNAMEs.
  • Lowering a TTL only after a change: caches can keep the old answer for up to the old TTL.

After every change, query the record with a lookup tool such as dig. Asking the authoritative server A DNS server that gives the official answers for a domain or zone. Full definition of authoritative server directly shows the new value regardless of caches. When unsure which records a service needs, check with the DNS provider.

Sources