Guides · updated 4 Oct 2026
DNS records explained
What A, AAAA, CNAME, MX, NS, TXT, CAA, SOA and PTR records do, how TTL caching works, how a DNS lookup is resolved and what DNSSEC adds.
The Domain Name System (DNS) turns a name like example.com into the information computers need, such as the server's address and where to deliver email. Each piece of information is a resource record. This guide covers the record types in the DNS and email panel of your Domain Statistics report.
How a DNS lookup works
A few roles are involved, defined in RFC 9499:
- Your device's stub resolver passes the question to a recursive resolver, such as your internet provider's.
- If the recursive resolver doesn't already have a cached answer, it starts at the root servers. IANA lists 13 root server identities, lettered a to m, which are actually "a network of hundreds of servers in many countries" (IANA root servers).
- The root servers refer the resolver to the servers for the top-level domain, such as .uk or .com. Those refer it to the domain's own authoritative servers, which hold the actual records. This handover, called delegation, works through NS records in the parent zone.
- The resolver returns the answer and caches it for up to the record's TTL.
The main record types
Type numbers are from the IANA DNS parameters registry. The examples use placeholder names and addresses.
example.com. 3600 IN A 192.0.2.10
example.com. 3600 IN AAAA 2001:db8::10
www.example.com. 3600 IN CNAME example.com.
example.com. 3600 IN MX 10 mail.example.com.
example.com. 86400 IN NS ns1.example.net.
example.com. 3600 IN TXT "v=spf1 include:_spf.example.net ~all"
example.com. 3600 IN CAA 0 issue "ca.example.net"
A and AAAA
An A record (type 1) holds an IPv4 address (RFC 1035). An AAAA record (type 28) holds a 128-bit IPv6 address (RFC 3596). A website usually has at least one A record, and often an AAAA record too.
CNAME
A CNAME (type 5) makes one name an alias of another, its "canonical name". RFC 1034 says that if a CNAME is present at a name, "no other data should be present". The top of a zone (the bare domain, such as example.com) must hold the zone's NS and SOA records. So in standard DNS, a CNAME belongs on names like www, not on the bare domain.
MX
An MX record (type 15) names a mail server for the domain, with a preference number. Lower values are preferred, so 10 is tried before 20. A domain that accepts no email can publish a "null MX", MX 0 ., defined in RFC 7505.
NS
NS records (type 2) list the authoritative nameservers for the zone. The nameservers set at your registrar become the delegation in the parent zone, so resolvers go to those servers. That happens even if you keep your up-to-date records with a different DNS host.
TXT
A TXT record (type 16) holds text strings. It is used for a lot of things: SPF (v=spf1 …), domain verification for services such as Google Search Console, and records at special "underscore" names such as _dmarc.example.com for DMARC and selector._domainkey.example.com for DKIM. IANA keeps a registry of these underscore names. See SPF, DKIM and DMARC explained.
CAA
A CAA record (type 257) lets a domain holder name the certificate authorities (CAs) allowed to issue certificates for the domain (RFC 8659). Its properties are issue, issuewild (for wildcard certificates) and iodef (where to report problems). 0 issue ";" means no CA may issue. More on this in SSL/TLS certificates explained.
SOA
Every zone has a single SOA (start of authority) record (type 6) at its top. Its fields are:
- the primary nameserver
- the mailbox of the person responsible, with the
@written as a dot - a serial number for the zone version
- refresh, retry and expire timers used between nameservers
- a MINIMUM value
All the timers are in seconds. Under RFC 2308, resolvers cache "this name doesn't exist" answers for the lower of the SOA's MINIMUM field and the SOA record's own TTL.
PTR
A PTR record (type 12) does the reverse: it maps an IP address back to a name. IPv4 addresses are written backwards under in-addr.arpa, so the address 10.2.0.52 is looked up at 52.0.2.10.in-addr.arpa (RFC 1035). IPv6 uses ip6.arpa. PTR records are controlled by whoever controls the IP address, as RFC 7208 notes, which is usually your hosting or email provider, not your DNS host. Mail providers check them. Gmail, for example, requires senders to have valid forward and reverse DNS (Gmail sender guidelines).
TTL: why changes take time to "propagate"
Every record has a TTL (time to live), measured in seconds. This is how long a resolver may cache the record before asking again. A TTL of 0 means "don't cache". RFC 2181 sets the maximum at 2,147,483,647 and says the TTL "specifies a maximum time to live, not a mandatory time to live". Resolvers may cap it lower.
"DNS propagation" is really just caches expiring. If a record has a TTL of 86,400 (one day), some people may see the old answer for up to a day after you change it. Lowering the TTL well before a planned change makes the switchover quicker.
DNSSEC basics
Ordinary DNS answers aren't signed. DNSSEC adds "data origin authentication and data integrity" (RFC 4033). In other words, a resolver can check that an answer really came from the zone's owner and hasn't been changed on the way. DNSSEC doesn't encrypt anything and doesn't protect against denial-of-service attacks.
It adds new record types:
- DNSKEY (48): the zone's public keys.
- RRSIG (46): signatures over sets of records.
- NSEC (47): signed proof that a name or record type doesn't exist.
- DS (43): published in the parent zone. It holds a hash of the child zone's key and links the two into a chain of trust.
For your own domain, the DS record goes to the registry through your registrar. If the signatures and the DS record stop matching, for example after a botched key change or a move to a new DNS host, a validating resolver treats the answers as bad and returns a server failure (RFC 4035). For people using a validating resolver, the domain stops working. Your report shows whether DNSSEC is enabled for the domain.
How to check DNS records yourself
- Run the domain through the Domain Statistics lookup and open the DNS and email panel.
- On macOS or Linux, use
dig(examples below). On Windows,nslookup -type=MX example.comdoes the same job. - If you've moved DNS hosts, check that the nameservers set at your registrar (and shown in the report) are the ones your new DNS host told you to use.
dig example.com A +short
dig example.com MX +short
dig _dmarc.example.com TXT +short
dig example.com CAA +short
dig -x 192.0.2.10 +short
Record type numbers and limits above are from the IETF and IANA documents listed, as checked in October 2026. For definitions of other terms, see the glossary.
Sources
- rfc-editor.org — DNS concepts – zones, the NS and SOA records at the top of a zone, the rule that no other data should sit alongside a CNAME, and how a mailbox is written as a domain name
- rfc-editor.org — record types A, NS, CNAME, SOA, PTR, MX, TXT; MX preference (lower preferred); SOA fields; TTL in seconds; IN-ADDR.ARPA reverse mapping
- rfc-editor.org — TTL is unsigned, 0 to 2147483647 (2^31 - 1), and is a maximum rather than a mandatory time to live
- rfc-editor.org — negative caching TTL taken from the SOA MINIMUM field and the SOA's own TTL
- rfc-editor.org — AAAA record (type 28) for IPv6 and IP6.ARPA reverse mapping
- rfc-editor.org — null MX – a domain announcing it accepts no mail
- rfc-editor.org — CAA record – lets a domain holder name the CAs authorised to issue certificates; issue, issuewild and iodef properties; 0 issue ";" requests no issuance
- rfc-editor.org — DNS terminology – stub resolver, recursive resolver, authoritative server, delegation, glue
- rfc-editor.org — DNSSEC adds data origin authentication and data integrity; it doesn't provide confidentiality or DoS protection; DS/DNSKEY chain of trust
- rfc-editor.org — a validating resolver returns a server failure when signatures don't validate
- rfc-editor.org — PTR records are under the control of whoever controls the IP address
- support.google.com — Gmail requires sending domains or IPs to have valid forward and reverse DNS (PTR) records
- iana.org — official record type codes (A 1, NS 2, CNAME 5, SOA 6, PTR 12, MX 15, TXT 16, AAAA 28, DS 43, RRSIG 46, NSEC 47, DNSKEY 48, CAA 257) and the underscored names such as _dmarc and _domainkey
- iana.org — the 13 root server identities (a to m), made up of hundreds of servers worldwide
Facts checked on 4 Oct 2026. Rules and figures change — check the source if it matters.