Skip to content
HOSTETHICAL
All guides

Guides · 9 min read ·

DNS Records Explained: A, AAAA, CNAME, MX, TXT and More

DNS records explained simply: what A, AAAA, CNAME, MX, TXT, NS and CAA records do, how TTL works, SPF, DKIM and DMARC for email, and mistakes to avoid.

DNS records are the instructions stored in your domain's DNS zone that tell the internet where to send traffic for your domain. The main types of DNS records are A and AAAA (point a name to an IPv4 or IPv6 address), CNAME (make one name an alias of another), MX (route incoming email), TXT (hold text for verification and email security such as SPF, DKIM and DMARC) and NS (name the servers in charge of the domain). Every record has a name, a type, a value and a TTL that controls how long it can be cached.

What a DNS record looks like

Whichever DNS panel you use, every record has the same four parts. MX and SRV records add a fifth, the priority.

  • Host or name: the name the record applies to. @ means the root domain itself, www means www.yourdomain.in, and mail means mail.yourdomain.in.
  • Type: A, AAAA, CNAME, MX, TXT and so on.
  • Value: where the name points. Panels also call it "points to", "target" or "data".
  • TTL: time to live, the number of seconds resolvers may cache the answer.

In the standard zone-file format that DNS servers use, records look like this:

yourdomain.in.       3600  IN  A      203.0.113.10
www.yourdomain.in.   3600  IN  CNAME  yourdomain.in.

The IP addresses in this guide (203.0.113.x and 2001:db8::) are reserved for documentation. Always use the real values your host or email provider gives you.

Types of DNS records at a glance

RecordWhat it doesExample value
APoints a name to an IPv4 address203.0.113.10
AAAAPoints a name to an IPv6 address2001:db8::10
CNAMEMakes a name an alias of another nameyourdomain.in
MXNames the servers that receive email for the domain10 mx1.mailprovider.example
TXTStores text: SPF, DKIM, DMARC, ownership verificationv=spf1 include:_spf.mailprovider.example ~all
NSNames the authoritative nameserversns1.hostethical.com
SOAZone details: primary nameserver, serial number, timersCreated automatically
CAALists which certificate authorities may issue SSL for the domain0 issue "letsencrypt.org"
SRVPoints a specific service to a host and port10 5 5060 sip.provider.example
PTRReverse DNS: maps an IP address back to a nameSet by whoever controls the IP

A and AAAA records

The A record is the most important record for a website. It maps a name to an IPv4 address such as 203.0.113.10. The AAAA ("quad-A") record does the same for an IPv6 address. When you connect a domain to hosting without changing nameservers, this is the record you edit.

  • Most sites need an A record for the root (@) and either an A record or a CNAME for www.
  • Several A records on the same name are allowed. Resolvers return all of them and browsers pick one, which is useful for load balancing but a problem if one of them is an old server.
  • Only add an AAAA record if your site genuinely works over IPv6. A wrong AAAA record is worse than none, because IPv6-capable devices, which are common on Indian mobile networks, try it first.
  • A wildcard record (*) answers for any subdomain that does not have its own record.

CNAME records

A CNAME (canonical name) record says "this name is an alias; go and look up that other name instead". Typical uses are pointing www to your root domain, or shop.yourdomain.in to a hostname given by a store or landing-page platform. If the target's IP address changes, the alias follows automatically.

  • A name that has a CNAME cannot have any other record. That is why you cannot put a CNAME on the root domain, which must also hold NS and SOA records. Some DNS providers offer an ALIAS, ANAME or "flattening" feature to work around this.
  • A CNAME value is always a hostname, never an IP address.
  • Avoid chains of CNAMEs pointing to other CNAMEs; each hop adds another lookup.

MX records

MX (mail exchanger) records tell other mail servers where to deliver email addressed to your domain. Each one has a priority number; the lowest number is tried first and higher numbers act as backups.

yourdomain.in.  3600  IN  MX  10  mx1.mailprovider.example.
yourdomain.in.  3600  IN  MX  20  mx2.mailprovider.example.
  • The value must be a hostname with its own A or AAAA record. It must not be an IP address or a CNAME.
  • Use exactly the records your email provider lists, and delete your old provider's MX records when you switch, or some mail will keep going to the old mailboxes.
  • MX records only affect incoming mail. Whether your outgoing mail lands in the inbox depends on SPF, DKIM and DMARC.

Setting up email on your own domain for the first time? Our guide to a custom email domain explains the options.

SPF, DKIM and DMARC: TXT records for email deliverability

TXT records hold free-form text, and their biggest job today is email authentication. Since February 2024, Gmail and Yahoo require anyone sending in bulk (more than 5,000 messages a day to Gmail accounts) to have SPF, DKIM and DMARC in place, and every sender to have at least SPF or DKIM. Without them, mail from your domain is far more likely to land in spam or be rejected outright.

RecordHostWhat it provesValue starts with
SPF@Which servers may send mail for your domainv=spf1
DKIMselector._domainkeyThe message was signed by an authorised sender and not alteredv=DKIM1
DMARC_dmarcWhat receivers should do when checks fail, and where to send reportsv=DMARC1

SPF: who is allowed to send

v=spf1 include:_spf.mailprovider.example include:newsletter.example ~all

Your domain may have only one SPF record. If you use several services, such as office email plus a newsletter tool, merge their include: entries into a single record. SPF also has a limit of ten DNS lookups, so do not keep piling on includes for services you no longer use. Ending with ~all (soft fail) is the safe default; -all (hard fail) is stricter.

DKIM: a signature on every message

Your email provider signs each outgoing message with a private key and gives you the matching public key to publish in DNS. The host includes a "selector" name chosen by the provider:

selector1._domainkey.yourdomain.in.  3600  IN  TXT  "v=DKIM1; k=rsa; p=MIIBIjANBgkqh..."

Copy the host and value exactly as given; DKIM keys are long and a single missing character breaks them. Some providers use a CNAME record for DKIM instead of TXT.

DMARC: the policy that ties them together

_dmarc.yourdomain.in.  3600  IN  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.in"

DMARC passes when SPF or DKIM passes and matches the domain in the visible From address. Start with p=none, which only collects reports. Once the reports show all your genuine mail passing, move to p=quarantine (send failures to spam) and eventually p=reject.

Verification TXT records for Google Search Console

Many services ask you to prove you own a domain by adding a TXT record containing a unique code. Google Search Console is the one most site owners meet first:

  1. In Search Console, add a property and choose Domain rather than URL prefix. A domain property covers http, https, www and every subdomain.
  2. Copy the TXT value Google shows. It looks like google-site-verification=abc123...
  3. In your DNS editor, add a TXT record with host @ and paste the value.
  4. Wait a few minutes and click Verify. If it fails, wait an hour and try again.
  5. Leave the record in place. Google checks it periodically, and removing it can unverify the property.

Microsoft 365, Facebook business domain verification and most email marketing tools work the same way. A domain can hold many TXT records on the root; only SPF must be a single record.

NS and SOA records

NS records list the nameservers that are authoritative for your domain. They exist in two places: at the registry, which is what you change when you "change nameservers" at your registrar, and inside the zone itself. For domains using HostEthical DNS, they are ns1.hostethical.com and ns2.hostethical.com. The SOA (start of authority) record is created automatically and holds the primary nameserver, an admin contact and a serial number that increases with every change. You will rarely need to touch it.

CAA, SRV and PTR records

  • CAA records restrict which certificate authorities may issue SSL certificates for your domain. They are optional, but if you add one that does not include the authority your host uses, certificate issuance and renewal will fail. See our guide to SSL certificates.
  • SRV records point a named service, such as internet telephony, to a host and port. The provider gives you the exact values.
  • PTR records provide reverse DNS, mapping an IP address back to a name. They are controlled by whoever owns the IP address, not by your domain's DNS. They matter mainly if you run your own mail server on a VPS.

What is TTL, and what value should you use?

TTLSecondsWhen to use it
5 minutes300Before and during a planned change, or while testing
1 hour3600A sensible default for most records
4 hours14400Records that rarely change
1 day86400Records that almost never change, such as NS

A lower TTL means changes reach everyone faster, at the cost of more DNS queries; for a small site the difference visitors notice is negligible. The professional habit is to lower the TTL a day before a planned change, make the change, then raise it again once everything works.

How to look up a domain's DNS records

dig yourdomain.in A +short
dig yourdomain.in MX +short
dig yourdomain.in TXT +short
dig _dmarc.yourdomain.in TXT +short
dig yourdomain.in NS +short
nslookup -type=mx yourdomain.in

dig is built into macOS and Linux; nslookup also works on Windows. Online DNS lookup tools do the same from a browser. To see which nameservers are registered at the registry, use a WHOIS lookup.

Common DNS mistakes

  1. Two SPF records. Both fail. Merge them into one.
  2. A CNAME on the root, or next to other records on the same name.
  3. A doubled domain name. Most panels add your domain automatically, so typing www.yourdomain.in in the host field creates www.yourdomain.in.yourdomain.in. Type just www.
  4. MX records pointing to an IP address or a CNAME.
  5. Editing the wrong DNS. If your nameservers point somewhere else, records in your registrar's panel do nothing.
  6. Stale AAAA records left behind after moving hosts.
  7. Setting DMARC to reject on day one, before checking that every service sending as your domain passes.
  8. Deleting old-looking verification TXT records that a service still checks.

Every domain registered with HostEthical includes a free DNS editor for all of these record types, and you can choose from 700+ extensions on our domain pricing page.

Register your domain with a free DNS editor and free WHOIS privacy where the registry allows it. Search domains →

Frequently asked questions

What is the difference between an A record and a CNAME?

An A record points a name directly to an IP address, while a CNAME points a name to another name, which is then looked up in turn. Use an A record for the root domain and CNAMEs for aliases such as www or subdomains.

How many DNS records can a domain have?

For normal use there is no practical limit: a domain can have many A, MX, TXT and CNAME records. The main restrictions are one SPF record per domain and no other records on a name that has a CNAME.

How long do DNS record changes take to work?

Most changes take effect within the previous TTL of the record, often between five minutes and a few hours. Nameserver changes can take up to 48 hours.

Do I need SPF, DKIM and DMARC if I only send a few emails?

Yes. Gmail requires every sender to have at least SPF or DKIM, and having all three greatly reduces the chance of your mail landing in spam or your domain being spoofed.