Resources
DNS, explained without the hand-waving.
What each record does, how zones move between nameservers, and why mail fails when a policy record is wrong. Written from operating it, not from a glossary.
Record types
Record types
- What is a DNS A record?The A record points a hostname at an IPv4 address. It is the most frequently used record in a DNS zone.
- What is a AAAA record?The AAAA record is the IPv6 counterpart of the A record: it points a hostname at an IPv6 address.
- What is a CNAME record?The CNAME record makes one name an alias of another. Everything else about the target is inherited.
- What is an MX record?The MX record says which servers accept mail for a domain, and in which order.
- What is a TXT record?The TXT record holds free text. In practice it carries the policies that keep mail and certificates honest.
- What is an NS record?NS records name the authoritative nameservers for a zone. They are what a delegation actually is.
- What is a PTR record?PTR records are used for reverse DNS: from an IP address back to the associated hostname.
- What is an SOA record?The SOA record holds the administrative data of a zone: its primary nameserver, its contact, and the timers for transfers.
- What is an SRV record?The SRV record publishes where a specific service runs: its host, its port, and how requests should be distributed.
- What is a CAA record?The CAA record says which certificate authority may issue certificates for your domain — and who to notify if somebody tries anyway.
Reference
Reference
- GlossaryEvery abbreviation and every term used on this site — authoritative, resolver, zone, delegation, PONS, SOA, AXFR, TTL, SPF, DKIM, DMARC, DNSSEC — explained in one sentence.
Zones and transfers
Zones and transfers
- What is a primary DNS zone?The primary zone — historically the master — is the writable copy of a zone. Every change starts here.
- What is a secondary DNS zone?The secondary zone — historically the slave — is a read-only copy of the zone, kept current by transfer from the primary.
- What is a DNS query?A DNS query is the request a client sends to get an answer about a name — an address, a mail server, a policy record.
- What is a TTL?The TTL is how long a resolver may keep an answer before asking again. It decides how fast a change becomes visible.
- What is DNS propagation?Propagation is the wait between a change on the primary and the moment every resolver in the world sees it.
- What are glue records?Glue records break the circular lookup that appears when a nameserver lives inside the domain it serves.
Mail and security
Mail and security
- What is an SPF record?SPF publishes which servers may send mail for your domain. Receivers check the sending address against it.
- What is DKIM?DKIM signs outgoing mail with a key whose public half lives in your DNS. The signature survives forwarding.
- What is DMARC?DMARC tells receivers what to do when SPF and DKIM disagree with the visible sender, and where to send reports.
- What is DNSSEC?DNSSEC signs the records in a zone so a resolver can prove the answer it received is the one you published.
- What is reverse DNS?Reverse DNS resolves an address back to a name. For mail servers it is a requirement, not a nicety.
- What is dynamic DNS?Dynamic DNS keeps a name pointed at a host whose address changes, by letting the host update its own record.
Our own record standard
What every zone here carries, and why — SPF, DKIM, DMARC, CAA, TLSRPT and a real SOA contact.