What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
DNS records are typed instructions stored in a domain’s DNS zone. They tell resolvers where a website or server is, which systems receive email, how a service is verified, which certificate authorities may issue certificates, and how specialized network services should be located. A record is not the website or mail system itself; it is the published information that helps clients find and use those systems.
This guide explains the record types you are most likely to encounter, where records are managed, how to inspect them, and how to troubleshoot changes without taking down other services.
How DNS works
When someone enters a domain name, their device asks a recursive DNS resolver for an answer. The resolver checks its cache and, when necessary, follows delegation from the DNS root and top-level domain to the domain’s authoritative nameservers. An authoritative server returns the zone data, and the resolver caches it for the record’s TTL (time to live). The application then uses the result.
DNS is more than an address directory: it also carries mail routing, service discovery, delegation, authentication policies, certificate restrictions, and DNSSEC keys. The core resource-record format is defined in RFC 1035.
Recommended Free Tools
#1 Best Overall
What a DNS record contains
The generic zone-file form is owner-name. TTL class type record-data. Most dashboards hide the class (normally IN) and may accept @, a short host label, or a full hostname.
| Field | Meaning |
|---|---|
| Name/Host | The domain or subdomain to which the record applies |
| Type | The function, such as A, MX, TXT, or CNAME |
| Content/Value/Target | Type-specific data, such as an IP address or hostname |
| TTL | How long a resolver may cache the answer |
| Priority/Preference | Ordering used by types such as MX and SRV |
| Proxy or status | A provider-specific control, not a universal DNS field |
For example:
www.example.com. 300 IN A 192.0.2.10
example.com. 3600 IN MX 10 mail.example.com.
example.com. 3600 IN TXT "v=spf1 include:example.net -all"
Where DNS records are managed
Edit records at the provider whose nameservers are authoritative for the domain—not automatically at the registrar. A registrar registers the name; a hosting company, CDN, dedicated DNS service, or cloud platform may host the authoritative zone.
Find the delegated nameservers with:
dig NS example.com +short
If the result lists a DNS provider’s nameservers, use that provider’s zone editor. Changing records in a registrar dashboard that is not authoritative has no effect. Changing the nameservers themselves is a high-impact operation that can alter the website, email, verification, certificates, APIs, and DNSSEC for the entire domain.
Common DNS record types
A: IPv4 address
An A record maps a hostname to an IPv4 address:
example.com. 300 IN A 192.0.2.10
Use it when a service supplies a fixed IPv4 address. Multiple A records can distribute answers, but they do not provide health-aware failover, session persistence, or geographic routing by themselves.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →AAAA: IPv6 address
AAAA maps a hostname to an IPv6 address:
example.com. 300 IN AAAA 2001:db8::10
A domain can publish both A and AAAA records. An incorrect or stale AAAA record can make a site fail for IPv6 users even while IPv4 tests succeed. IPv6 record details are specified in RFC 3596.
CNAME: hostname alias
A CNAME points one hostname to another hostname:
www.example.com. 300 IN CNAME example.hosting-provider.com.
- The target is a hostname, never an IP address.
- A traditional CNAME generally cannot coexist with other data at the same owner name.
- A normal CNAME cannot occupy the zone apex (such as
example.com) because the apex also needs SOA and NS data. Providers may offer CNAME flattening, ALIAS, or ANAME-style features; these are provider-specific or distinct mechanisms, not interchangeable rules. - Chains add lookup steps and failure points, and the final target must resolve to usable address records.
MX: inbound email routing
MX records identify mail servers that receive email:
example.com. 3600 IN MX 10 mail1.example.com.
example.com. 3600 IN MX 20 mail2.example.com.
Lower preference numbers are preferred. The target should be a hostname with A or AAAA records, not an IP address. MX controls inbound delivery; it does not authorize a service to send mail. SMTP behavior is covered by RFC 5321.
TXT: text, verification, and policy data
TXT stores text associated with a name. Services use it for ownership checks, SPF, DKIM keys, DMARC, certificate-authority restrictions, and other configuration. A TXT record’s meaning comes from its content; it is not automatically an SPF, DKIM, or DMARC record. Long values may appear as several quoted character strings, and multiple TXT records can coexist for different services.
SPF policy in TXT
Current deployments publish SPF policy in TXT records, for example:
example.com. 3600 IN TXT "v=spf1 ip4:192.0.2.10 include:mail.example.net -all"
ip4: and ip6: authorize addresses; include: imports another policy; ~all is a soft fail and -all a hard fail. SPF has a limit of 10 DNS-lookup-causing mechanisms, including nested includes. Merge authorized senders into one policy for a name rather than publishing multiple SPF policies, which can produce a permanent error. See RFC 7208.
DKIM: signed-mail verification
DKIM publishes a public key under a selector:
selector1._domainkey.example.com. 3600 IN TXT "v=DKIM1; k=rsa; p=..."
The sender signs with the matching private key; recipients retrieve the public key from DNS. Use the selector and exact value supplied by the email provider rather than inventing a key. The protocol is defined in RFC 6376.
DMARC: policy and reporting
DMARC is published at _dmarc:
_dmarc.example.com. 3600 IN TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com"
p=none monitors, quarantine asks receivers to treat failures suspiciously, and reject requests rejection. DMARC depends on alignment between the visible From domain and authenticated SPF and/or DKIM; it cannot repair broken authentication. Start with monitoring and move toward enforcement after legitimate senders pass. See RFC 7489.
NS: authoritative nameservers
NS records identify authoritative servers for a zone or delegated subdomain:
blog.example.com. 3600 IN NS ns1.other-provider.example.
blog.example.com. 3600 IN NS ns2.other-provider.example.
Do not replace NS records when you merely need an A, CNAME, MX, or TXT entry. NS changes transfer authority and can affect every service.
SOA: zone metadata
The Start of Authority record contains the designated master, responsible-party mailbox in DNS notation, serial number, refresh, retry, expire, and negative-caching-related timing values. Authoritative providers normally generate and maintain SOA records; most users should not create one manually.
PTR: reverse DNS
PTR maps an IP address back to a hostname in in-addr.arpa (IPv4) or ip6.arpa (IPv6). The IP address owner—usually a cloud provider, ISP, or host—normally controls it. Reverse DNS is particularly important for mail reputation and infrastructure identification.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
SRV: service location
SRV identifies a protocol service by priority, weight, port, and target:
_sip._tcp.example.com. 3600 IN SRV 10 60 5060 sipserver.example.com.
Only applications that support SRV use it; it does not redirect ordinary web traffic. The format is defined in RFC 2782.
CAA: permitted certificate authorities
CAA restricts which certificate authorities may issue TLS certificates:
example.com. 3600 IN CAA 0 issue "letsencrypt.org"
It is a restriction, not a certificate. An incorrect CAA record can block legitimate issuance. See RFC 8659.
DNSSEC: DS and DNSKEY
DNSKEY publishes a zone’s DNSSEC public key; DS connects a child zone’s key to its parent delegation. DNSSEC lets validating resolvers authenticate DNS data, but it does not encrypt DNS queries or website traffic. The record relationship is specified in RFC 4034.
HTTPS and SVCB: modern connection hints
SVCB and its web-specific HTTPS form advertise connection parameters such as supported protocols and alternative endpoints. They are newer, specialized records defined by RFC 9460; most sites should add them only when a platform explicitly instructs them to.
Quick reference
| Type | Main job | Typical value |
|---|---|---|
| A | IPv4 address | 192.0.2.10 |
| AAAA | IPv6 address | 2001:db8::10 |
| CNAME | Hostname alias | target.example.net. |
| MX | Inbound mail | 10 mail.example.com. |
| TXT | Verification and policy | "v=..." |
| NS | Authority/delegation | ns1.provider.example. |
| SOA | Zone metadata | Provider-managed |
| PTR | Reverse IP lookup | host.example.com. |
| SRV | Service location | 10 5 443 service.example.com. |
| CAA | Allowed certificate authority | 0 issue "..." |
| DS/DNSKEY | DNSSEC chain and keys | DNSSEC data |
| HTTPS/SVCB | Connection hints | Structured parameters |
TTL and DNS “propagation”
In www.example.com. 300 IN A 192.0.2.10, 300 is five minutes. It is the maximum caching interval a resolver may use for that answer, not a guaranteed worldwide change timer. A resolver may already hold an older answer under a previous, longer TTL; negative answers are cached under rules described in RFC 2308. Lowering TTL shortly before editing cannot retroactively shorten caches that already exist. Browser, operating-system, application, router, and CDN caches can also outlive DNS caching.
How to add or change a record safely
- Confirm authority with
dig NS example.com +short. - Open that authoritative provider’s DNS dashboard.
- Back up or document the existing zone before a migration or nameserver change.
- Create or edit the requested type and use the exact value supplied by the service.
- Check whether the dashboard expects
@, a relative label such aswww, or a full hostname. - Choose an appropriate TTL and save.
- Query the authoritative server directly.
- Query independent recursive resolvers.
- Test the actual website, mail flow, certificate issuance, verification, or application connection.
For example, Cloudflare’s documented flow is DNS Records, Add record, choose a type, and complete its type-specific fields; its proxy status and CNAME-flattening controls are provider features, not standard DNS fields. See Cloudflare’s record-creation guide and record-management documentation.
DNS lookup tools
Browser lookup
Google Admin Toolbox Dig provides a browser interface. Enter a name, select A, AAAA, CNAME, MX, NS, TXT, SOA, CAA, or SRV, and compare the answer with the provider’s instructions. A web tool queries a particular resolver and may be unavailable or rate-limited; it is not a view of every record in your authoritative dashboard.
dig
Linux and macOS commonly provide dig through DNS utilities:
dig example.com
dig example.com A +short
dig example.com AAAA +short
dig example.com CNAME +short
dig example.com MX +short
dig example.com TXT +short
dig example.com NS +short
dig example.com SOA +short
dig example.com CAA +short
dig _sip._tcp.example.com SRV +short
dig @1.1.1.1 example.com A
dig @8.8.8.8 example.com MX
dig +trace example.com
dig example.com A +dnssec
dig example.com DNSKEY
dig example.com DS
dig -x 192.0.2.10
NOERRORmeans the DNS response completed without a DNS-level error.NXDOMAINmeans the queried name does not exist in that delegation context.SERVFAILis not the same as “no record”; it can indicate DNSSEC failure, unreachable authoritative servers, or another resolver problem.ANSWER SECTIONcontains the requested answer;AUTHORITY SECTIONmay contain delegation or SOA data.ADindicates that a validating resolver considers the answer DNSSEC-authenticated.
Windows nslookup
nslookup example.com
nslookup -type=A example.com
nslookup -type=AAAA example.com
nslookup -type=MX example.com
nslookup -type=TXT example.com
nslookup -type=NS example.com
nslookup example.com 1.1.1.1
nslookup is convenient for quick checks; dig usually exposes more diagnostic detail.
host
host example.com
host -t MX example.com
host -t TXT example.com
host -t NS example.com
Reading an answer correctly
- The name queried may differ from the name returned, especially with CNAMEs.
- The requested type may appear alongside related records included in the response.
- A recursive answer may be cached; an authoritative answer is the zone owner’s current publication.
- An IP address proves only that DNS returned an address. It does not prove that the server, TLS certificate, firewall, or application is healthy.
- A CDN or reverse proxy may intentionally return edge addresses rather than the origin.
Troubleshooting by symptom
The website does not load
- Compare A and AAAA answers; remove or correct stale IPv6 data if the IPv6 service is not configured.
- Verify that
wwwand the apex point to the intended destinations. - Check whether a CNAME was entered where the provider required an A record, or vice versa.
- If a proxy is enabled, test the proxy and origin according to the provider’s instructions; the public address may not be the origin.
Email does not arrive
- Check MX preference and confirm each target has address records.
- Remove obsolete MX entries only after confirming the migration plan.
- Ensure SPF is one merged policy and stays within lookup limits.
- Verify the DKIM selector, DMARC name (
_dmarc), and reverse DNS with the mail or IP provider.
Verification fails
- Confirm the record was added at the authoritative provider.
- Match the exact host label and value, including selector or underscore labels.
- Check TXT quoting and long-value splitting according to the dashboard’s instructions.
- Do not delete an older token until the service confirms it is no longer required.
The change appears delayed
Query the authoritative server and two recursive resolvers:
dig @authoritative-nameserver.example example.com A
dig @1.1.1.1 example.com A
dig @8.8.8.8 example.com A
If authority is correct but recursive answers differ, caching or negative caching is likely. If authority is wrong, the issue is in the zone or the wrong provider was edited.
SERVFAIL appears
Check dig example.com A +dnssec, dig example.com DNSKEY, and dig example.com DS. Broken signatures, keys, DS data, or unreachable authoritative servers can cause validation failure. Removing random DNSSEC records is not a safe repair; use the DNS provider’s documented recovery process.
When managed DNS is worth considering
A registrar’s basic DNS editor is sufficient for many small sites. Consider managed DNS when you need DNSSEC assistance, API or infrastructure-as-code control, auditability, health checks, traffic steering, secondary DNS, high-volume operations, or integrated CDN, WAF, DDoS, and proxy services.
- Cloudflare DNS combines authoritative DNS with optional CDN and proxy features. DNS is available on all Cloudflare plans; Enterprise quotes can use monthly query volume. Proxying can make public lookups show Cloudflare addresses rather than the origin.
- Google Cloud DNS suits teams already operating in Google Cloud; see its records documentation. It is cloud infrastructure, so account and usage administration are part of the trade-off.
- Amazon Route 53 integrates authoritative DNS with AWS health checks and routing policies; pricing is usage-based and should be checked on its current pricing page.
- Dedicated alternatives include DNS Made Easy, NS1, EasyDNS, and Akamai Edge DNS. Compare reliability, DNSSEC, API access, routing, support, pricing, limits, portability, and whether proxy behavior is introduced.
Key distinctions to remember
- A is an IPv4 address; AAAA is IPv6; CNAME is a hostname alias.
- MX routes inbound mail, while SPF, DKIM, and DMARC govern sender authorization, signatures, and policy.
- NS changes authority; ordinary record edits change data inside the current zone.
- DNSSEC authenticates signed DNS data but does not provide encryption.
- Multiple addresses are not the same as health-aware failover.
- “Propagation” means caches expiring and resolvers refreshing—not one synchronized event.
Frequently Asked Questions
Can I have multiple A records?
Yes. Multiple A or AAAA records can distribute answers, but basic DNS does not perform health checks, session persistence, geographic routing, or guaranteed failover.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Best Value
- Used Book in Good Condition
Can I have multiple CNAME records?
A hostname normally cannot have multiple CNAME records or a CNAME alongside other data at the same name. Use one alias or the record type required by the service.
Can a CNAME point to an IP address?
No. A CNAME target is a hostname. Use A for IPv4 or AAAA for IPv6.
What does @ mean in a DNS dashboard?
@ usually represents the zone apex, such as example.com, but confirm the dashboard’s notation before saving.
Do DNS records need a trailing dot?
Zone files use a trailing dot to mark a fully qualified name. Many dashboards add or normalize it automatically; follow the provider’s format.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsWho controls reverse DNS?
The owner of the IP address—usually your cloud provider, ISP, or hosting company—normally controls the PTR record.
Does DNS affect SEO?
DNS is an infrastructure dependency, not a direct ranking signal in the same way as page content. Outages, slow or incorrect resolution, and inaccessible HTTPS can make a site unavailable to users and crawlers.
What happens if I delete an MX or NS record?
Deleting MX data can stop inbound mail. Deleting or changing authoritative NS delegation can make the entire zone unavailable or move control to another provider. Document the zone and verify dependencies first.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

