Skip to content
netscanner

DNS records explained: which record does what?

Website, email or SSL certificate: behind every domain there is a handful of DNS records. This guide shows what the most important record types do and where the typical mistakes happen in practice.

Updated on

What is a DNS record?

The Domain Name System (DNS) translates names such as www.example.ch into technical information: IP addresses, responsible mail servers, verification keys or references to other names. All information about a domain lives in a zone on the authoritative name servers. Each line of that zone is a resource record, or DNS record for short.

A record always consists of the same parts: name, TTL, class (practically always IN), type and value.

www.example.ch.   3600   IN   A   192.0.2.10

The trailing dot marks a fully qualified name. In most DNS management interfaces, you only enter the part before the domain, such as “www”, or “@” for the domain itself.

The most important record types at a glance

Type Purpose Example value
A IPv4 address of a name 192.0.2.10
AAAA IPv6 address of a name 2001:db8::10
CNAME Alias to another name shops.example.com.
MX Responsible mail server 10 mx1.example.com.
TXT Free text, e.g. SPF or verifications "v=spf1 mx -all"
NS Authoritative name servers of the zone ns1.example.com.
SOA Administrative data of the zone ns1.example.com. hostmaster.example.ch. 2026100201 …
CAA Allowed certificate authorities 0 issue "letsencrypt.org"
PTR Reverse DNS: from IP to name mail.example.ch.
SRV Service with target host and port 10 5 443 sip.example.com.

A and AAAA

An A record maps a name to an IPv4 address, an AAAA record to an IPv6 address. Multiple A records for the same name are allowed; resolvers then spread requests across all addresses. Only set AAAA if the server actually responds over IPv6. Otherwise, visitors with an IPv6 connection wait for a timeout before the browser falls back to IPv4. To see who owns an IP address and where it is located, use the IP lookup.

CNAME

A CNAME is an alias: the resolver follows the reference and uses the target’s A and AAAA records. This is handy for external services such as ecommerce or landing page platforms, because the provider can change its IP addresses without you having to adjust anything.

www.example.ch.    3600  IN  CNAME  example.ch.
shop.example.ch.   3600  IN  CNAME  shops.example.com.

MX

MX records define which servers accept email for the domain. The number is the priority: the lowest value is tried first. The target must be a hostname with an A or AAAA record, not an IP address and not a CNAME.

example.ch.  3600  IN  MX  10 mx1.example.com.
example.ch.  3600  IN  MX  20 mx2.example.com.

TXT

TXT records contain text and today are mainly used for security and verification: SPF, DKIM, DMARC and confirmations for services such as Google Search Console or Microsoft 365. A name may have several TXT records, but only one of them may start with v=spf1. Texts longer than 255 characters are split into several strings, which the recipient joins back together. Our guide How to set up SPF, DKIM and DMARC explains how to build the mail records correctly.

NS and SOA

NS records name the authoritative name servers. What counts is the delegation at the registry; the NS records in your zone should match it. The SOA record contains administrative data: primary name server, contact address (with a dot instead of @), serial number and timers.

example.ch.  3600  IN  SOA  ns1.example.com. hostmaster.example.ch. (
                 2026100201  ; Serial
                 7200        ; Refresh
                 3600        ; Retry
                 1209600     ; Expire
                 3600 )      ; Minimum (negative caching)

The last value determines how long resolvers remember that a name does not exist.

CAA

CAA records define which certificate authorities may issue SSL certificates for your domain. Without CAA, any authority may issue them. If CAA records exist but your provider is missing, issuance or renewal fails. For wildcard certificates, there is also issuewild.

example.ch.  3600  IN  CAA  0 issue "letsencrypt.org"
example.ch.  3600  IN  CAA  0 iodef "mailto:security@example.ch"

PTR

The PTR record is the reverse: it maps an IP address to a name and lives in the in-addr.arpa (IPv4) or ip6.arpa (IPv6) zones. It is managed by the owner of the address range, not by the domain owner. It matters for mail servers: many recipients check whether the sending IP has a matching reverse record.

10.2.0.192.in-addr.arpa.  3600  IN  PTR  mail.example.ch.

SRV

SRV records describe under which host and port a specific service is reachable, such as SIP telephony or XMPP. The name follows the pattern _service._protocol, and the value contains priority, weight, port and target.

_sip._tls.example.ch.  3600  IN  SRV  10 5 443 sip.example.com.

TTL: how long answers stay valid

The TTL (time to live) specifies in seconds how long resolvers may cache an answer. 3600 means one hour. A high TTL reduces queries and speeds up resolution on average, but delays changes. A low TTL makes changes visible quickly.

Proven values:

  • 3600 seconds as the default for most records
  • 300 seconds before planned changes, set in good time
  • 86400 seconds for very stable records such as NS

A lowered TTL only takes effect once the old TTL has expired in the caches. Our guide to DNS propagation explains why.

Common mistakes and how to avoid them

CNAME on the root domain

The root domain (apex, e.g. example.ch without www) always carries SOA and NS records. A CNAME, however, must not have any other records alongside it, so it is not allowed at the apex. Some interfaces refuse it, others save it anyway, with unpredictable consequences for mail and verifications. The solution: direct A and AAAA records or a provider feature such as CNAME flattening or ALIAS, where the DNS provider resolves the target itself and serves A records.

CNAME alongside other records

The same rule applies to every name. A classic mistake: a CNAME exists for mail.example.ch, and a TXT or MX record is added to the same name. The result then varies depending on the resolver and software. Put such records on a different name or replace the CNAME with A and AAAA records.

Forgotten records after a migration

When switching DNS providers, often only the obvious records are carried over: the root domain and www. Missing are MX, SPF, DKIM selectors, DMARC, verification TXT records, SRV or the autodiscover CNAME. The website works, but emails land in spam or stop arriving altogether. So follow the domain migration checklist and export the old zone completely.

Other classics

  • MX points to an IP or a CNAME: Enter a hostname with an A or AAAA record.
  • Two SPF records: This causes an error during evaluation. Combine everything into a single record.
  • Old A records left in place: If a name points to both the old and the new server, some visitors end up on the wrong one.
  • Missing trailing dot: In zone files, mx1.example.com without a dot is expanded to mx1.example.com.example.ch.

Check your records

With NetScanner’s DNS lookup, you see live what the public resolver 1.1.1.1 currently returns for A, AAAA, CNAME, MX, NS, TXT, SOA and CAA, including a DNSSEC notice. For mail records, the email checker also tests SPF, DMARC and common DKIM selectors in a single pass.

Frequently asked questions

What is the difference between an A record and a CNAME record?

An A record points directly to an IPv4 address. A CNAME points to another name, whose address the resolver then looks up on its own.

Can I set a CNAME for the root domain?

Not according to the DNS standard, because the root domain already has SOA and NS records and a CNAME cannot coexist with other records. Use A and AAAA records or a provider feature such as CNAME flattening or ALIAS.

What TTL makes sense for DNS records?

For most records, 3600 seconds (one hour) is a good default. Before planned changes, lower the TTL to 300 seconds well in advance and raise it again afterwards.

Who sets the PTR record for my IP address?

The reverse DNS record is managed by the owner of the IP address range, which is usually your hosting provider or internet provider. You cannot set it in your domain's zone.