To make a domain load your website, its DNS must point at your server’s IP address. You do this with A records (and AAAA records for IPv6) wherever your domain’s DNS is managed.
First find out where your DNS is managed. It is usually your registrar, but if you changed nameservers to a DNS service or your host, the records live there instead. Run dig NS example.com +short to see which nameservers are in charge.
A record or nameservers?
Hosts often give you two ways to connect a domain, and they do different things:
| Method | What you change | Who manages DNS afterwards | Best when |
|---|---|---|---|
| Point an A record | One or two records at your current DNS provider | You, where it is now | Email or other services already use the domain’s DNS |
| Change nameservers | The domain’s nameservers, at the registrar | The host | A new domain with nothing else on it, and you want the host to handle everything |
Pointing records is the safer choice for an existing domain, because nothing else moves. Changing nameservers hands every record to the host; anything you do not recreate there, including email, stops working. See what a nameserver is.
Steps
- Find your server’s IP address. Your host shows it in the control panel or welcome email. On the server itself,
curl -4 ifconfig.meprints its public IPv4 address. - Open the DNS settings for the domain in your registrar or DNS provider.
- Set the A record for the bare domain. Name
@(or blank), type A, value your server’s IP. If an A record for@already exists, edit it rather than adding a second one; two A records split visitors between two servers. - Add www. Either an A record for
wwwwith the same IP, or a CNAME fromwwwto your bare domain. - Add AAAA records only if your server has a working IPv6 address.
- Save, and leave the TTL at the default unless you are planning a move.
- Tell the server about the domain. The web server or control panel must have a site configured for this domain name, or it will show a default page.
Subdomains
A subdomain such as blog.example.com or shop.example.com is just another name in the same zone. Add an A record with the name blog and the server’s IP, or a CNAME if a service gives you a hostname to point at. Subdomains can point at different servers from the main site.
Behind Cloudflare
If your DNS is on Cloudflare, each A and CNAME record has a proxy switch. With the orange cloud on, visitors connect to Cloudflare, which fetches from your server; dig then shows Cloudflare’s addresses, not yours. That is expected. Turn the proxy off (grey cloud) while you set up the server and its certificate, then turn it on and set SSL mode to Full (strict). See what a CDN is.
Check it
dig example.com A +short
dig www.example.com +short
Both should return your server’s IP. If they show an old address, the change is still propagating.
If it does not work
| Symptom | Likely cause |
|---|---|
dig shows the old IP | The change is still propagating, or you edited the wrong provider: check dig NS example.com +short |
dig shows the right IP, browser shows the old site | Your computer’s cache: flush your DNS cache |
| Right IP, but a default “Welcome to Nginx” or host page | The server has no site configured for this domain name |
| DNS_PROBE_FINISHED_NXDOMAIN | Record missing, or the domain’s nameservers are wrong |
| ERR_CONNECTION_REFUSED | DNS is fine; the server or its firewall is refusing connections |
www works but the bare domain does not, or the reverse | One of the two records is missing |
Then add HTTPS
Once the domain resolves to the server, issue a certificate. See free SSL with Let’s Encrypt. Certificate tools check the domain points at your server first, so this always comes after the DNS change.
Leave MX records alone unless you are changing email too. Pointing the website elsewhere does not affect email, but deleting MX records stops mail arriving.
Related
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.

