A hosting company tells you to "add an A record", a website builder asks for a CNAME, and a CDN says either will do. Which is right? The CNAME vs A record question comes up constantly, and the answer depends on what you are pointing at and where in your domain the record sits. This article explains the difference in practical terms and gives you a simple way to decide.
The one-sentence difference
An A record points a name at an IP address. A CNAME record points a name at another name. That is the whole distinction; everything else follows from it.
; A record: name -> IPv4 address
www.example.com. 3600 IN A 203.0.113.25
; CNAME record: name -> another name
shop.example.com. 3600 IN CNAME stores.platform-host.com.
When a resolver looks up shop.example.com and finds the CNAME, it starts a second lookup for stores.platform-host.com and returns whatever A or AAAA records that name has. The visitor ends up at the platform's servers, and the platform is free to change its IP addresses without asking you to edit anything.
How they compare
| A record | CNAME record | |
|---|---|---|
| Points to | An IPv4 address (AAAA for IPv6) | A host name |
| Allowed at the root domain | Yes | No (standard DNS) |
| Can coexist with other records on the same name | Yes | No |
| Follows the target's IP changes automatically | No | Yes |
| Extra lookup step | No | Yes, usually cached |
| Valid as an MX or NS target | Yes (the host the MX names) | No |
The rules that limit CNAMEs
A CNAME must be alone on its name
The DNS standards say that if a name has a CNAME, it cannot have any other data. So shop.example.com can have a CNAME, or it can have A, MX and TXT records, but not both. Many DNS control panels will refuse to save a conflicting combination; some older ones will save it and produce unpredictable results.
No CNAME at the domain apex
Your bare domain (example.com, often written as @) must have NS and SOA records, and usually MX and TXT records too. Because a CNAME cannot coexist with those, a standard CNAME at the apex is not allowed. This is why platforms usually ask you to put an A record on the root and a CNAME on www.
Do not point MX or NS records at a CNAME
The host name used in an MX or NS record should have its own A or AAAA record. Pointing them at an alias breaks the rules in RFC 2181 and can cause some mail servers to reject or delay delivery.
The workaround: ALIAS, ANAME and CNAME flattening
Because so many services want you to point your root domain at a host name, many DNS providers offer a non-standard record type that behaves like a CNAME at the apex. It goes by different names, such as ALIAS, ANAME or "CNAME flattening". The provider's own servers look up the target name and answer queries for your root with the resulting IP addresses, so to the outside world it looks like an ordinary A record.
It works well, but it is a provider feature rather than a DNS standard. If you move to a DNS host that does not support it, you will need to replace it with plain A records.
Which should you use? A decision guide
- Is the record at your root domain? Use an A record (plus AAAA if the server has IPv6), or your provider's ALIAS feature if the target only gives you a host name.
- Does the name need other records, such as MX or TXT? Use A records. A CNAME there would conflict.
- Are you pointing at a third-party platform (website builder, CDN, helpdesk, email marketing tracking domain)? Use a CNAME if they give you a host name. They can then move servers without breaking your site.
- Are you pointing at your own server with a fixed IP, such as a VPS or dedicated server? An A record is simplest and avoids an extra lookup.
- Do several subdomains point at the same server? Consider one A record (for example
server1.example.com) and CNAMEs from the others to it. When the IP changes, you update one record instead of ten.
Typical setups
| Situation | Root (@) | www |
|---|---|---|
| Your own VPS or dedicated server | A to server IP | A to server IP, or CNAME to the root |
| Hosted website builder | A to the IPs they publish | CNAME to the host name they give |
| CDN in front of your site | ALIAS/flattened CNAME, or the CDN's A records | CNAME to the CDN host name |
| Subdomain for a SaaS tool (help, status) | Unchanged | Unchanged; add a CNAME on the subdomain |
Does a CNAME slow your site down?
In theory, yes: a CNAME adds one more lookup. In practice the effect is usually tiny, because resolvers cache both the CNAME and the target, and popular platforms' host names are almost always already cached. The flexibility of letting the provider manage its own IP addresses is normally worth far more than the few milliseconds involved. Avoid long chains (a CNAME pointing to a CNAME pointing to another), which do add up and are harder to debug.
Checking what you have
To see whether a name is an alias or a direct address, look it up with the DNS lookup tool or run dig www.example.com +short. A CNAME shows up as a host name followed by the final IP address. If you are adding a custom domain for a site that will need HTTPS, check afterwards with the SSL checker that the platform has issued a certificate for the new name, since many do this automatically only once the DNS record is in place.
Key takeaways
- A records point to IP addresses; CNAMEs point to other host names.
- A CNAME cannot share a name with other records and cannot normally be used at the root domain.
- Use CNAMEs for third-party platforms that give you a host name; use A records for your own fixed-IP servers and for the apex.
- ALIAS or CNAME flattening solves the root-domain problem, but only on providers that support it.