Resources
Glossary
Every abbreviation and every term that appears on this site, written out and explained in one sentence — so nothing here has to be looked up somewhere else.
CTPF terms
Our own terms
| Short | Written out | What it means |
|---|---|---|
| PONS | Point of NameServer | One of our twelve locations that answers DNS queries. Frankfurt is the primary PONS, the other eleven are secondary. |
| CTPF | CertThor PlatForms | The company behind this service, CertThor PlatForms Ltd. |
| CTPFDNS | CTPF DNS | The DNS service on this site: zones, nameservers and the record standard. |
| CDP | ControlDeskPanel | The hosting control panel of the platform, where zones and services are managed. |
| CDPCMS | CDP Content Management System | The content system of the same platform. |
| CDPGuard | CDP Guard | The firewall module of the platform. |
Words, not abbreviations
Terms you meet on this site
| Term | What it means |
|---|---|
| Authoritative | A nameserver is authoritative for a zone when it holds the zone itself and answers from it — its answer is the source, not a copy from somebody else. Our twelve PONS are authoritative for the zones we host. |
| Resolver | The server that asks on behalf of a user — at the provider, in the router, at a public service. It does not hold zones; it collects answers from authoritative servers and keeps them for the length of the TTL. |
| Recursive | The way a resolver works: it follows the chain from the root down to the zone until it has the answer, instead of handing the work back to the client. |
| Zone | The set of records belonging to one domain, held as one unit. A zone starts with its SOA record and lists everything below the domain. |
| Primary | The writable copy of a zone. Every change starts there. Historically called the master. Read more |
| Secondary | A read-only copy of the zone, kept current by transfer from the primary. Historically called the slave. Read more |
| Delegation | The parent zone pointing at your nameservers. Until the delegation is switched, the world still asks whoever was there before. Read more |
| Serial | The version number of a zone in its SOA record. If it does not rise, the secondaries ignore the change. |
| Propagation | The wait between a change on the primary and the moment every resolver in the world sees it — caused by caches, not by us. Read more |
| Glue record | The address of a nameserver that lives inside the domain it serves, held by the parent to break the circular lookup. Read more |
| Root and TLD | The two levels above your domain: the root, and the top level domain such as .com or .de. Both are asked before anyone reaches your nameservers. |
| Registrar and registry | The registry runs a top level domain; the registrar is where you hold your domain and where the delegation and the DNSSEC fingerprint are entered. |
| Failover | A record is switched to a standby target when a check says the first one no longer answers. |
| Health check | The repeated test behind a failover: is the host still answering, from several locations. |
| Caching | Resolvers keep an answer for the length of its TTL instead of asking again. This is why a change is not visible everywhere at once. |
| Zone transfer | The copy of a zone from the primary to a secondary — complete as AXFR, as a difference as IXFR. |
Record types
What sits in a zone
| Short | Written out | What it means |
|---|---|---|
| A | Address record | Points a name at an IPv4 address. Read more |
| AAAA | IPv6 address record | Points a name at an IPv6 address. Read more |
| CNAME | Canonical Name | Makes one name an alias of another. Read more |
| MX | Mail Exchanger | Names the servers that accept mail for a domain, and in which order. Read more |
| NS | Name Server | Names the authoritative nameservers of a zone — the delegation itself. Read more |
| PTR | Pointer record | Resolves an address back to a name. Read more |
| SOA | Start of Authority | Holds the administrative data of a zone: primary, contact, serial and timers. Read more |
| SRV | Service record | Publishes host, port and weighting of a specific service. Read more |
| TXT | Text record | Holds free text; in practice the policy records for mail and certificates. Read more |
| CAA | Certification Authority Authorization | Says which certificate authority may issue for your domain. Read more |
Operation
How a zone moves and stays current
| Short | Written out | What it means |
|---|---|---|
| TTL | Time To Live | How long a resolver may keep an answer before asking again. Read more |
| AXFR | Authoritative Full Zone Transfer | The full copy of a zone that a secondary fetches from the primary. |
| IXFR | Incremental Zone Transfer | The same as AXFR, but only the difference since the last serial. |
| NOTIFY | Zone change notification | The message the primary sends so the secondaries fetch the zone at once instead of waiting for a timer. |
| DDNS | Dynamic DNS | A host updates its own record when its address changes. Read more |
| FQDN | Fully Qualified Domain Name | A name written out completely, up to the root — no missing suffix. |
| rDNS | reverse DNS | The lookup from an address back to a name, built on PTR records. Read more |
Mail and security
The records that decide whether mail arrives
| Short | Written out | What it means |
|---|---|---|
| SPF | Sender Policy Framework | Publishes which servers may send mail for your domain. Read more |
| DKIM | DomainKeys Identified Mail | Signs outgoing mail with a key whose public half sits in your zone. Read more |
| DMARC | Domain-based Message Authentication, Reporting and Conformance | Tells receivers what to do when SPF and DKIM disagree with the visible sender. Read more |
| rua | Reporting URI for aggregate data | The address in a DMARC record that aggregate reports are sent to. |
| iodef | Incident Object Description Exchange Format | The contact in a CAA record that is notified when somebody tries to misissue a certificate. |
| TLSRPT | TLS Reporting | A record under which reports about failed transport encryption are collected. |
| DNSSEC | Domain Name System Security Extensions | Signs the records of a zone so an answer can be proven genuine. Read more |
| DS | Delegation Signer | The fingerprint deposited at the registrar that ties your signed zone to the parent. |
| TLS | Transport Layer Security | The encryption of a connection; SSL is its older name. |
Network
How answers find their way
| Short | Written out | What it means |
|---|---|---|
| Anycast | — | The same address announced from several locations; the network routes a query to the nearest one. |
| Unicast | — | One address at one location — the plain case, without routing tricks. |
| GeoDNS | Geographic DNS | The answer depends on where the query comes from. |
| ECS | EDNS Client Subnet | An extension that tells the authoritative server roughly where the asking client sits, so GeoDNS can answer accurately. |
| EDNS | Extension Mechanisms for DNS | The extension that lets DNS carry more than the original protocol allowed. |
| DDoS | Distributed Denial of Service | An attack from many sources at once, aimed at making a service unreachable. |
| IP | Internet Protocol | The addressing of the internet; IPv4 is the older, IPv6 the current version. |
| API | Application Programming Interface | The machine interface that does everything the panel does. |
| WHOIS | — | The lookup of registrar, status and expiry of a domain. |
Business terms
SLA — Service Level Agreement: what we commit to in writing. Our service level
AUP — Acceptable Use Policy: what a zone here may and may not be used for. Our acceptable use policy
VAT — Value Added Tax: the tax not included in the listed prices.