DNS record types explained

A, AAAA, CNAME, MX, TXT, NS, CAA and SRV: what each DNS record does, with real examples you can copy.

4–6 minutes
Network switch with many blue patch cables

A domain’s DNS zone is a list of records. Each record has a name (which hostname it applies to), a type, a value and a TTL. These are the types you will meet most.

TypePoints a name toExample value
AAn IPv4 address203.0.113.10
AAAAAn IPv6 address2001:db8::10
CNAMEAnother hostnameexample.com.
MXA mail server, with a priority10 mail.example.com.
TXTFree text, used for verification and email security"v=spf1 mx -all"
NSThe nameservers for the domain or a subdomainns1.provider.net.
CAAWhich certificate authorities may issue certificates0 issue "letsencrypt.org"
SRVA service’s host and port10 5 5060 sip.example.com.

A and AAAA

The core records. example.com with an A record of 203.0.113.10 sends visitors to that server. Add an AAAA record only if the server really has a working IPv6 address; a wrong AAAA record breaks the site for visitors on IPv6.

CNAME

An alias. www.example.com CNAME example.com means “look up whatever example.com points to”. Two rules catch people out:

  • A name with a CNAME cannot have any other record.
  • The bare domain (example.com itself, often shown as @) cannot be a CNAME, because it must also hold NS and SOA records. Some DNS providers offer “CNAME flattening” or ALIAS records to get around this.

MX

Tells other mail servers where to deliver email for the domain. The number is a priority: lower is tried first. MX must point to a hostname that has an A record, never to an IP address or a CNAME.

TXT

Holds text. Used for domain verification with services, and for email security: SPF, DKIM and DMARC all live in TXT records.

NS

Says which nameservers are authoritative. The NS records at your registrar decide who controls the whole domain. NS records inside your zone can hand a subdomain to a different provider.

CAA

Optional, but a good safety step: it lists which certificate authorities may issue certificates for your domain. Others must refuse.

SOA and PTR

Two more records you will meet, though you rarely edit them:

  • SOA (start of authority) sits at the top of every zone. It names the primary nameserver and an admin contact, and holds timers, including how long resolvers should cache a “this name does not exist” answer. Your DNS host manages it.
  • PTR records do the reverse of an A record: they map an IP address back to a name. They live in a special zone owned by whoever controls the IP address, which is your hosting provider, not your domain’s DNS. They matter mostly for mail servers, because receiving servers distrust mail from an IP without a matching PTR record. You set them in your host’s control panel, often called “reverse DNS”.

A typical setup

A small business with its website on its own server and email on a hosted provider might have:

NameTypeValuePurpose
@A203.0.113.10Website on the bare domain
wwwCNAMEexample.com.www follows the bare domain
@MX1 smtp.google.com.Mail to Google Workspace
@TXT"v=spf1 include:_spf.google.com -all"SPF: Google may send for us
google._domainkeyTXT"v=DKIM1; k=rsa; p=MIIB..."DKIM public key
_dmarcTXT"v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com"DMARC policy
@CAA0 issue "letsencrypt.org"Only Let’s Encrypt may issue certificates

The mail values differ by provider; copy them exactly from your provider’s setup page. Microsoft 365, for example, uses an MX record like 0 example-com.mail.protection.outlook.com.

Check any record from the command line

dig asks for a specific type:

dig example.com A +short
dig www.example.com CNAME +short
dig example.com MX +short
dig example.com TXT +short
dig _dmarc.example.com TXT +short
dig -x 203.0.113.10 +short

The last one looks up the PTR record for an IP address. On Windows, nslookup -type=MX example.com does the same job. Add @1.1.1.1 to any dig command to ask a public resolver rather than your own, or @ followed by your nameserver to see exactly what it holds, without any caching.

Choosing a TTL

SituationTTL
Normal, stable records3600 (1 hour) to 86400 (1 day)
A change planned in the next day or two300 (5 minutes), set in advance
Records behind a CDN or failover serviceWhatever the provider sets, often 300 or less

Shorter TTLs mean more lookups but faster changes. There is little benefit in going below 300 seconds, and some resolvers ignore very short values anyway. See what DNS propagation is.

Common mistakes

  • Two SPF records. A domain must have one TXT record starting v=spf1. Two make SPF fail. Merge them into one.
  • MX pointing at a CNAME or an IP address. Use a hostname with an A record.
  • A stale AAAA record after moving servers. Visitors on IPv6 still reach the old server.
  • **Forgetting www.** The bare domain works but www does not resolve, or still points at the old host.
  • Editing records at the wrong provider. Changes only count at the provider your nameservers point to. Check with dig NS example.com +short.

Names, @ and the trailing dot

Most DNS panels write the bare domain as @ and add your domain to any name you type, so www means www.example.com. In raw zone files, a hostname ending in a dot is complete; one without a dot has the domain added. When a panel shows mail.example.com.example.com, a missing or extra dot is usually why.

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.