Open the DNS settings for any domain and you are faced with a list of abbreviations: A, AAAA, CNAME, MX, TXT, NS and more. Each one of these DNS record types answers a different question about your domain, such as "which server hosts the website?" or "where should email be delivered?". Knowing what each type does makes it much easier to follow instructions from a hosting company or email provider, and to spot mistakes before they cause an outage.
How a DNS record is structured
Every record, whatever its type, has the same five parts. In the standard zone-file format they look like this:
www.example.com. 3600 IN A 203.0.113.25
name TTL class type value
The name is the host the record belongs to. In most control panels you enter only the part before your domain, and @ means the domain itself (the "apex" or "root"). The TTL is how many seconds resolvers may cache the answer. The class is almost always IN (internet). The type and value are what this article is about.
The common DNS record types at a glance
| Type | Purpose | Example value |
|---|---|---|
| A | Maps a name to an IPv4 address | 203.0.113.25 |
| AAAA | Maps a name to an IPv6 address | 2001:db8::25 |
| CNAME | Makes a name an alias of another name | shop.example-host.com. |
| MX | Lists mail servers for the domain | 10 mx1.mailhost.net. |
| TXT | Holds text: SPF, DKIM, DMARC, verification | "v=spf1 include:_spf.google.com ~all" |
| NS | Names the authoritative name servers | ns1.dnshost.net. |
| SOA | Zone metadata: primary server, serial, timers | (generated by your DNS host) |
| SRV | Locates a service on a host and port | 10 5 5060 sip.example.com. |
| CAA | Restricts which CAs may issue certificates | 0 issue "letsencrypt.org" |
| PTR | Maps an IP address back to a name | mail.example.com. |
Address records: A and AAAA
An A record is the most basic record there is: it says "this name lives at this IPv4 address". When you point a domain at a web server, you are usually creating an A record for @ and another for www. An AAAA record ("quad-A") does the same for an IPv6 address. You can have several A records for one name; resolvers return them all and clients pick one, which gives a simple form of load distribution.
Only add an AAAA record if your server is genuinely reachable over IPv6. A wrong AAAA record is a quiet source of problems, because visitors on IPv6 networks will try it first and may see timeouts while everyone else is fine.
CNAME: an alias
A CNAME (canonical name) record says "this name is really that other name; go and look that one up instead". It is commonly used to point www or a subdomain at a platform such as a website builder, CDN or helpdesk tool, which can then change its IP addresses without you touching your DNS.
Two rules trip people up. First, a name with a CNAME cannot have any other record at all, so you cannot put a CNAME alongside MX or TXT records on the same name. Second, because the domain apex always has NS and SOA records, a standard CNAME is not allowed at the root of your domain. Some DNS providers offer a workaround under names like ALIAS, ANAME or "CNAME flattening", which resolves the target behind the scenes and serves it as an A record.
MX: where email goes
An MX record (mail exchanger) tells other mail servers where to deliver email for your domain. Each MX has a priority number; lower numbers are tried first, and equal numbers share the load:
example.com. 3600 IN MX 10 mx1.mailhost.net.
example.com. 3600 IN MX 20 mx2.mailhost.net.
The target of an MX record must be a host name that has its own A or AAAA record, not an IP address and not a CNAME. If a domain has no MX record, senders fall back to its A record, which is rarely what you want.
TXT: the multi-purpose record
A TXT record holds arbitrary text. In practice it has become the place where services store machine-readable settings. You will meet it for:
- SPF, at the domain itself, listing which servers may send mail for it.
- DKIM, at
selector._domainkey, publishing the public key used to sign mail. - DMARC, at
_dmarc, telling receivers how to handle failing mail. - Domain verification strings from search consoles, cloud providers and SaaS tools.
A single name can carry many TXT records, but it must have only one SPF record (one starting v=spf1). You can confirm your email-related TXT records with the SPF, DKIM and DMARC checker.
NS and SOA: the zone's own paperwork
NS records name the servers that hold the authoritative copy of your zone. They exist in two places: in the parent zone (set through your registrar) and inside your own zone. Both sets should match. The SOA record (start of authority) is created automatically by your DNS host and contains the primary name server, an administrator contact, a serial number that changes with each edit, and timers used by secondary servers. Most website owners never need to edit it.
The specialist record types
SRV
An SRV record lets clients discover which host and port provide a service, with priority and weight values for failover. It is named like _service._protocol.name, for example _sip._tcp.example.com, and is used by VoIP, chat and some directory services. The value format is priority, weight, port, target.
CAA
A CAA record (certification authority authorisation) lists which certificate authorities are allowed to issue SSL/TLS certificates for your domain. Authorities are required to check it before issuing, so it is a simple safeguard against mis-issuance.
PTR
A PTR record does the reverse of an A record: it maps an IP address to a name. PTR records live in special reverse zones controlled by whoever owns the IP address, usually your hosting or internet provider, rather than in your domain's zone. Mail servers check them heavily.
Seeing your own records
To see which of these record types your domain currently publishes, run it through our DNS lookup tool and select "all", or query a single type. Comparing that output with the table above is a quick way to audit a domain you have inherited.
Key takeaways
- A and AAAA records point names at IP addresses; CNAME records point names at other names.
- A CNAME cannot share a name with any other record and cannot normally sit at the domain apex.
- MX records route email and must point to host names, not IP addresses.
- TXT records carry SPF, DKIM, DMARC and verification data; keep only one SPF record per domain.
- NS, SOA, SRV, CAA and PTR are less visible but matter for delegation, services, certificates and email reputation.