Resources

DNS, explained without the hand-waving.

What each record does, how zones move between nameservers, and why mail fails when a policy record is wrong. Written from operating it, not from a glossary.

Record types

Record types

  • What is a DNS A record?The A record points a hostname at an IPv4 address. It is the most frequently used record in a DNS zone.
  • What is a AAAA record?The AAAA record is the IPv6 counterpart of the A record: it points a hostname at an IPv6 address.
  • What is a CNAME record?The CNAME record makes one name an alias of another. Everything else about the target is inherited.
  • What is an MX record?The MX record says which servers accept mail for a domain, and in which order.
  • What is a TXT record?The TXT record holds free text. In practice it carries the policies that keep mail and certificates honest.
  • What is an NS record?NS records name the authoritative nameservers for a zone. They are what a delegation actually is.
  • What is a PTR record?PTR records are used for reverse DNS: from an IP address back to the associated hostname.
  • What is an SOA record?The SOA record holds the administrative data of a zone: its primary nameserver, its contact, and the timers for transfers.
  • What is an SRV record?The SRV record publishes where a specific service runs: its host, its port, and how requests should be distributed.
  • What is a CAA record?The CAA record says which certificate authority may issue certificates for your domain — and who to notify if somebody tries anyway.

Reference

Reference

  • GlossaryEvery abbreviation and every term used on this site — authoritative, resolver, zone, delegation, PONS, SOA, AXFR, TTL, SPF, DKIM, DMARC, DNSSEC — explained in one sentence.

Zones and transfers

Zones and transfers

  • What is a primary DNS zone?The primary zone — historically the master — is the writable copy of a zone. Every change starts here.
  • What is a secondary DNS zone?The secondary zone — historically the slave — is a read-only copy of the zone, kept current by transfer from the primary.
  • What is a DNS query?A DNS query is the request a client sends to get an answer about a name — an address, a mail server, a policy record.
  • What is a TTL?The TTL is how long a resolver may keep an answer before asking again. It decides how fast a change becomes visible.
  • What is DNS propagation?Propagation is the wait between a change on the primary and the moment every resolver in the world sees it.
  • What are glue records?Glue records break the circular lookup that appears when a nameserver lives inside the domain it serves.

Mail and security

Mail and security

  • What is an SPF record?SPF publishes which servers may send mail for your domain. Receivers check the sending address against it.
  • What is DKIM?DKIM signs outgoing mail with a key whose public half lives in your DNS. The signature survives forwarding.
  • What is DMARC?DMARC tells receivers what to do when SPF and DKIM disagree with the visible sender, and where to send reports.
  • What is DNSSEC?DNSSEC signs the records in a zone so a resolver can prove the answer it received is the one you published.
  • What is reverse DNS?Reverse DNS resolves an address back to a name. For mail servers it is a requirement, not a nicety.
  • What is dynamic DNS?Dynamic DNS keeps a name pointed at a host whose address changes, by letting the host update its own record.

Our own record standard

What every zone here carries, and why — SPF, DKIM, DMARC, CAA, TLSRPT and a real SOA contact.

See the standard