Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A DNS A record connects a domain name or subdomain to an IPv4 address. To make one work, add it to the DNS zone served by your domain’s authoritative nameservers, then allow time for cached answers to expire. An A record does not point to an IPv6 address—that is what an AAAA record is for.

What a DNS A record does

DNS records tell resolvers how to handle names in a domain. An A record contains a 32-bit Internet address: an IPv4 address. When someone looks up the name, DNS can return that address so a client can connect to the corresponding service.

For example, www.example.com. 3600 IN A 192.0.2.10 is a zone-file-style A record. The address 192.0.2.10 is reserved for documentation, not a real server destination. In this example, 3600 is the TTL in seconds.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A name can have more than one A record, such as when it is associated with multiple IPv4 addresses. RFC 1035 puts it plainly: “Hosts that have multiple Internet addresses will have multiple A records.” RFC 1035, section 3.4.1

#1 Best Overall

Choose A, AAAA, or CNAME based on the target

Record type What it points to Can other records share the name?
A An IPv4 address Yes, except that a name cannot also be a CNAME.
AAAA An IPv6 address Yes, except that a name cannot also be a CNAME.
CNAME Another DNS name No. A CNAME cannot coexist with other record data at the same name.

A CNAME is an alias, not an IP address. A resolver follows the alias to find the target name’s records. If the name already has a CNAME, remove or change it before adding an A record there; ordinary record data cannot coexist with a CNAME at one name under RFC 2181. See Google Cloud’s DNS records overview for these record roles.

How to create an A record

The labels and available settings differ among DNS providers, but the key requirement is the same: edit the zone that is authoritative for the domain. Adding a record to a dashboard zone that the domain does not use will not publish that change to the public DNS.

  1. Open the authoritative DNS zone. In your provider’s DNS dashboard, select the zone for the domain. Confirm that the domain delegates to this provider’s nameservers.
  2. Add a record set or DNS record. Choose the option to create a standard record, then select A.
  3. Enter the name and IPv4 address. Use the host label or fully qualified name expected by the provider—for example, www or www.example.com—and enter the intended IPv4 address. Check both for typos.
  4. Choose TTL and any provider-specific controls. Set a TTL if the provider allows it. If options such as proxy status are offered, understand how they affect responses before enabling them.
  5. Save and verify. Check the answer from the authoritative nameserver and then from a recursive resolver. If the domain uses different nameservers from the zone you edited, update the delegation or make the change in the zone that is actually authoritative.

For a provider-specific example, Google Cloud’s Cloud DNS quickstart describes creating a public managed zone, adding a record set of type A, and entering the IPv4 address. It separately explains that the domain must use the Cloud DNS nameservers for that zone to be published. Console labels and workflows can change; follow the current provider instructions for exact controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What TTL means for changes

TTL, or time to live, is the period a DNS record may be cached before it should be consulted again. A longer TTL can reduce repeated lookups, but a resolver that has cached an old address may continue to use it until its cached copy expires. A zero TTL means the record should be used only for the transaction in progress, not cached, according to RFC 1035.

Changing the authoritative record does not force every recursive or local cache to refresh at once. That is why there is no universal number of minutes after which every user will see an update. A nameserver-delegation change is a separate issue from changing a record within a zone.

Cloudflare TTL settings are provider-specific

Cloudflare’s TTL documentation, updated April 16, 2026, states that proxied records use an uneditable Auto TTL of 300 seconds. For DNS-only records, it lists a minimum of 30 seconds for Enterprise customers or 60 seconds for non-Enterprise customers, a maximum of one day, and an Auto setting of 300 seconds. Cloudflare also cautions that local DNS caches can make the observed delay longer than five minutes. These are Cloudflare settings, not universal DNS limits.

Rank #4
PUSR TCP232-302 TCP IP to Serial Support DNS DHCP Modbus Gateway Device Server RS232 to Ethernet Converter
  • ARM core, Cortex-M0 solution, equipped with deeply optimized TCP/IP protocol stack. It has low latency and strong scalability, stable and reliable
  • Supports custom webpage function to help users improve brand influence
  • Supports Modbus RTU to Modbus TCP protocol conversion and multi-host polling
  • Supports hardware and software watchdog, automatically restarts when the device goes down.
  • Versatile operation modes: TCP Server, TCP Client, UDP, HTTP client.

Cloudflare’s record-type documentation shows an example A record for www.example.com pointing to 192.0.2.1 with TTL 3600 and DNS-only status. That is an example configuration; it is not a recommended TTL or setup for every domain. Proxy status can change what clients receive and how TTL works, so do not assume a provider’s proxy controls apply elsewhere.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
WatchGuard Firebox T145 with 1 Year Standard Support - Tabletop Firewall, 2.5Gb, 1Gb & SFP Ports, Enterprise Security for Branch Locations (WGT145000+WGT1450061)
  • Watchguard T145 Firebox with 1 Year Standard Support License (WGT145001) - The Firebox T145 delivers enterprise-grade protection for branch offices and retail sites. With a blend of 2.5Gb, 1Gb, and SFP/SFP+ ports, it supports high throughput, AI-driven malware protection, and DNS filtering for robust network defense.
  • Standard Support covers software updates and round-the-clock emergency help. Add a Basic or Total Security Suite to activate IPS, gateway antivirus, and web filtering so threats are blocked before they reach users.
  • Standard Support provides reliable technical assistance and software updates for WatchGuard Firebox appliances. Offering 24x7 help for emergencies and business-hours support for routine needs, it ensures your network stays secure and operational.
  • Interfaces and deployment: 2.5Gb and 1Gb Ethernet with SFP or SFP+ fiber for clean aggregation and segmented backhaul at the edge.
  • Performance and scale: UTM up to 710 Mbps with inspection on; flexible VPN topologies for hub and spoke or mesh designs.

How to troubleshoot an A record

  • The lookup returns the wrong address or no address: Check that you edited the correct domain zone, that the name is spelled correctly, and that the A value is the intended IPv4 address.
  • The dashboard shows the record, but public DNS does not: Verify that the domain delegates to the nameservers for the zone you edited. A saved record in a non-authoritative zone is not the answer served for the domain.
  • You cannot add an A record at the name: Look for an existing CNAME at that exact name. A CNAME cannot share its name with A or other record data.
  • The authoritative answer is correct but a recursive lookup is old: The recursive resolver may have a cached answer. Compare the authoritative and recursive responses, and account for the TTL and local caching rather than treating one stale response as proof that the record is misconfigured.
  • The public answer differs from the expected origin address: If the provider offers proxying, check whether it is enabled. Proxy behavior is a separate layer from a DNS-only A record and can affect the response seen by clients.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.