Resources

Glossary

Every abbreviation and every term that appears on this site, written out and explained in one sentence — so nothing here has to be looked up somewhere else.

CTPF terms

Our own terms

ShortWritten outWhat it means
PONSPoint of NameServerOne of our twelve locations that answers DNS queries. Frankfurt is the primary PONS, the other eleven are secondary.
CTPFCertThor PlatFormsThe company behind this service, CertThor PlatForms Ltd.
CTPFDNSCTPF DNSThe DNS service on this site: zones, nameservers and the record standard.
CDPControlDeskPanelThe hosting control panel of the platform, where zones and services are managed.
CDPCMSCDP Content Management SystemThe content system of the same platform.
CDPGuardCDP GuardThe firewall module of the platform.

Words, not abbreviations

Terms you meet on this site

TermWhat it means
AuthoritativeA nameserver is authoritative for a zone when it holds the zone itself and answers from it — its answer is the source, not a copy from somebody else. Our twelve PONS are authoritative for the zones we host.
ResolverThe server that asks on behalf of a user — at the provider, in the router, at a public service. It does not hold zones; it collects answers from authoritative servers and keeps them for the length of the TTL.
RecursiveThe way a resolver works: it follows the chain from the root down to the zone until it has the answer, instead of handing the work back to the client.
ZoneThe set of records belonging to one domain, held as one unit. A zone starts with its SOA record and lists everything below the domain.
PrimaryThe writable copy of a zone. Every change starts there. Historically called the master. Read more
SecondaryA read-only copy of the zone, kept current by transfer from the primary. Historically called the slave. Read more
DelegationThe parent zone pointing at your nameservers. Until the delegation is switched, the world still asks whoever was there before. Read more
SerialThe version number of a zone in its SOA record. If it does not rise, the secondaries ignore the change.
PropagationThe wait between a change on the primary and the moment every resolver in the world sees it — caused by caches, not by us. Read more
Glue recordThe address of a nameserver that lives inside the domain it serves, held by the parent to break the circular lookup. Read more
Root and TLDThe two levels above your domain: the root, and the top level domain such as .com or .de. Both are asked before anyone reaches your nameservers.
Registrar and registryThe registry runs a top level domain; the registrar is where you hold your domain and where the delegation and the DNSSEC fingerprint are entered.
FailoverA record is switched to a standby target when a check says the first one no longer answers.
Health checkThe repeated test behind a failover: is the host still answering, from several locations.
CachingResolvers keep an answer for the length of its TTL instead of asking again. This is why a change is not visible everywhere at once.
Zone transferThe copy of a zone from the primary to a secondary — complete as AXFR, as a difference as IXFR.

Record types

What sits in a zone

ShortWritten outWhat it means
AAddress recordPoints a name at an IPv4 address. Read more
AAAAIPv6 address recordPoints a name at an IPv6 address. Read more
CNAMECanonical NameMakes one name an alias of another. Read more
MXMail ExchangerNames the servers that accept mail for a domain, and in which order. Read more
NSName ServerNames the authoritative nameservers of a zone — the delegation itself. Read more
PTRPointer recordResolves an address back to a name. Read more
SOAStart of AuthorityHolds the administrative data of a zone: primary, contact, serial and timers. Read more
SRVService recordPublishes host, port and weighting of a specific service. Read more
TXTText recordHolds free text; in practice the policy records for mail and certificates. Read more
CAACertification Authority AuthorizationSays which certificate authority may issue for your domain. Read more

Operation

How a zone moves and stays current

ShortWritten outWhat it means
TTLTime To LiveHow long a resolver may keep an answer before asking again. Read more
AXFRAuthoritative Full Zone TransferThe full copy of a zone that a secondary fetches from the primary.
IXFRIncremental Zone TransferThe same as AXFR, but only the difference since the last serial.
NOTIFYZone change notificationThe message the primary sends so the secondaries fetch the zone at once instead of waiting for a timer.
DDNSDynamic DNSA host updates its own record when its address changes. Read more
FQDNFully Qualified Domain NameA name written out completely, up to the root — no missing suffix.
rDNSreverse DNSThe lookup from an address back to a name, built on PTR records. Read more

Mail and security

The records that decide whether mail arrives

ShortWritten outWhat it means
SPFSender Policy FrameworkPublishes which servers may send mail for your domain. Read more
DKIMDomainKeys Identified MailSigns outgoing mail with a key whose public half sits in your zone. Read more
DMARCDomain-based Message Authentication, Reporting and ConformanceTells receivers what to do when SPF and DKIM disagree with the visible sender. Read more
ruaReporting URI for aggregate dataThe address in a DMARC record that aggregate reports are sent to.
iodefIncident Object Description Exchange FormatThe contact in a CAA record that is notified when somebody tries to misissue a certificate.
TLSRPTTLS ReportingA record under which reports about failed transport encryption are collected.
DNSSECDomain Name System Security ExtensionsSigns the records of a zone so an answer can be proven genuine. Read more
DSDelegation SignerThe fingerprint deposited at the registrar that ties your signed zone to the parent.
TLSTransport Layer SecurityThe encryption of a connection; SSL is its older name.

Network

How answers find their way

ShortWritten outWhat it means
Anycast—The same address announced from several locations; the network routes a query to the nearest one.
Unicast—One address at one location — the plain case, without routing tricks.
GeoDNSGeographic DNSThe answer depends on where the query comes from.
ECSEDNS Client SubnetAn extension that tells the authoritative server roughly where the asking client sits, so GeoDNS can answer accurately.
EDNSExtension Mechanisms for DNSThe extension that lets DNS carry more than the original protocol allowed.
DDoSDistributed Denial of ServiceAn attack from many sources at once, aimed at making a service unreachable.
IPInternet ProtocolThe addressing of the internet; IPv4 is the older, IPv6 the current version.
APIApplication Programming InterfaceThe machine interface that does everything the panel does.
WHOIS—The lookup of registrar, status and expiry of a domain.

Business terms

SLA — Service Level Agreement: what we commit to in writing. Our service level

AUP — Acceptable Use Policy: what a zone here may and may not be used for. Our acceptable use policy

VAT — Value Added Tax: the tax not included in the listed prices.

All resources