Ctrl + K
Network20 min read

Common DNS Record Types

A practical guide to the most common DNS record types, what they do, how their fields work, and when to use A, AAAA, CNAME, MX, TXT, NS, SOA, PTR, SRV and CAA records.

Published: 2026-10-05

DNS records are the individual pieces of information that tell DNS resolvers how a domain should work. When someone enters a domain name into a browser, sends an email, or connects to a service, DNS records help determine which servers and services are associated with that name.

Different DNS record types serve different purposes. An A record maps a hostname to an IPv4 address, an AAAA record maps it to IPv6, an MX record identifies mail servers, a CNAME creates an alias, and a TXT record stores text-based information used for purposes such as domain verification and email authentication.

Understanding the common record types makes it much easier to configure domains, troubleshoot DNS problems, set up email, connect services, and understand what a DNS lookup is actually returning.

What Is a DNS Record?

A DNS record is a structured entry stored in a DNS zone. It associates a domain name or hostname with information that DNS clients can retrieve.

A record has a type that determines how its value should be interpreted. For example, an A record contains an IPv4 address, while an MX record identifies a mail server and includes a priority value.

Record typeMain purpose
AMaps a hostname to an IPv4 address.
AAAAMaps a hostname to an IPv6 address.
CNAMECreates an alias from one hostname to another hostname.
MXSpecifies mail servers responsible for receiving email.
TXTStores arbitrary text data used for verification, authentication, and other purposes.
NSIdentifies the authoritative name servers for a DNS zone.
SOAContains administrative and synchronization information for a DNS zone.
PTRMaps an IP address back to a hostname for reverse DNS.
SRVSpecifies the location and port of a service.
CAASpecifies which certificate authorities are permitted to issue certificates for a domain.

Anatomy of a DNS Record

DNS zone files represent records using several fields. The exact presentation differs between DNS providers, but the same concepts appear repeatedly.

FieldMeaning
NameThe domain or hostname to which the record applies.
TTLHow long resolvers may cache the record before querying again.
ClassThe DNS record class; IN for Internet is by far the most common.
TypeDefines what the record means, such as A, MX, or TXT.
ValueThe data associated with the record.
example.com.  3600  IN  A  192.0.2.10

In this example, example.com has an A record with a TTL of 3600 seconds and the IPv4 address 192.0.2.10 as its value.

What Is an A Record?

An A record, or Address record, maps a domain name or hostname to an IPv4 address. It is one of the most commonly used DNS record types.

example.com.  3600  IN  A  192.0.2.10
www.example.com.  3600  IN  A  192.0.2.10

When a DNS resolver receives a query for the A record of example.com, it can return 192.0.2.10. A browser can then use that IPv4 address to establish a network connection to the server.

A domain can have multiple A records. This can be used to associate a hostname with multiple IPv4 addresses, although the exact behavior experienced by clients depends on the application, resolver, and infrastructure.

What Is an AAAA Record?

An AAAA record performs a similar role to an A record but stores an IPv6 address instead of an IPv4 address.

example.com.  3600  IN  AAAA  2001:db8::10

The name AAAA comes from the fact that an IPv6 address is four times the size of an IPv4 address. An A record and AAAA record can coexist for the same hostname, allowing clients to use either IPv4 or IPv6 depending on their network connectivity and address selection behavior.

A vs AAAA

RecordAddress familyExample
AIPv4192.0.2.10
AAAAIPv62001:db8::10

If a service supports both protocols, publishing both A and AAAA records can allow IPv4 and IPv6 clients to reach it.

What Is a CNAME Record?

A CNAME, or Canonical Name record, creates an alias from one hostname to another hostname. Instead of directly storing an IP address, the alias points to another DNS name.

www.example.com.  3600  IN  CNAME  example.com.

A resolver querying www.example.com can follow the CNAME to example.com and then resolve the target name to the appropriate address record.

⚠️ A CNAME points to a hostname, not directly to an IP address. A common configuration mistake is putting an IP address into a CNAME record.

CNAME Restrictions

A CNAME has special DNS semantics. A name that has a CNAME generally cannot simultaneously have other ordinary data records such as A, MX, or TXT records at the same name.

This is why a hostname used for a CNAME cannot normally also contain an independent MX or TXT record at exactly the same DNS name. Some DNS providers offer special features such as ALIAS or ANAME-like records to address related use cases at the zone apex.

CNAME vs A Record

CharacteristicACNAME
ValueIPv4 addressAnother hostname
Typical useDirectly associate a name with an IPv4 endpoint.Create an alias for another DNS name.
Can target a hostname?NoYes
Can normally coexist with other records at the same name?Yes, subject to DNS rules.No, a CNAME name generally cannot have other data records.

What Is an MX Record?

An MX, or Mail Exchange, record identifies the mail servers responsible for receiving email for a domain.

example.com.  3600  IN  MX  10 mail.example.com.
example.com.  3600  IN  MX  20 backup-mail.example.com.

The number before the mail server is the preference value. Lower values have higher preference, so a sender will normally try the server with preference 10 before the server with preference 20.

The hostname specified by an MX record must resolve to an address through appropriate address records. MX records do not contain the mail server's IP address directly.

Why MX Priority Matters

Multiple MX records allow a domain to specify multiple mail servers. The preference values indicate their relative priority.

MX preferenceMail serverTypical role
10mail.example.comPrimary mail server
20backup-mail.example.comLower-priority mail server

The exact mail delivery behavior also depends on the sending mail server and its retry logic. MX preference is not a general DNS load-balancing mechanism.

What Is a TXT Record?

A TXT record stores text associated with a DNS name. Although the record type is generic, TXT records are widely used for machine-readable configuration and verification data.

example.com.  3600  IN  TXT  "example-verification=abc123"

TXT records are commonly used for domain ownership verification, email authentication mechanisms such as SPF and DKIM-related data, DMARC policies, and service-specific verification.

TXT Records and SPF

SPF uses DNS TXT records to publish a policy describing which mail servers are authorized to send email for a domain.

example.com.  3600  IN  TXT  "v=spf1 include:mail.example.net -all"

The SPF syntax itself is separate from the DNS TXT record format. DNS provides the mechanism for publishing the text, while SPF defines how that text should be interpreted by mail systems.

TXT Records and DKIM

DKIM uses DNS to publish public-key information associated with a selector. The selector becomes part of the DNS name used to retrieve the DKIM record.

selector1._domainkey.example.com.  3600  IN  TXT  "v=DKIM1; p=PUBLIC_KEY_DATA"

The actual DKIM value can be significantly longer than this simplified example and may be split according to DNS presentation rules.

TXT Records and DMARC

DMARC policies are also published using TXT records. DMARC specifies how a receiving mail system should handle messages that fail applicable authentication alignment checks and can provide reporting instructions.

_dmarc.example.com.  3600  IN  TXT  "v=DMARC1; p=none"

What Is an NS Record?

An NS, or Name Server, record identifies the authoritative name servers for a DNS zone.

example.com.  86400  IN  NS  ns1.example-dns.net.
example.com.  86400  IN  NS  ns2.example-dns.net.

Authoritative name servers are responsible for providing authoritative answers for the zone. A domain's delegation at the parent zone also identifies the name servers responsible for the child zone.

NS Records vs Domain Registrar Settings

A common source of confusion is the difference between NS records inside a DNS zone and the name server delegation configured at the domain registrar or registry level.

The registrar configuration tells the parent DNS infrastructure which authoritative name servers should be used for the domain. The authoritative zone itself also contains NS records describing the zone's authoritative servers.

What Is an SOA Record?

SOA stands for Start of Authority. Every authoritative DNS zone has an SOA record containing administrative and zone-management information.

example.com.  3600  IN  SOA  ns1.example-dns.net. hostmaster.example.com. (
  2026092401
  3600
  600
  1209600
  300
)

The SOA record contains fields such as the primary name server, responsible-party mailbox, serial number, refresh interval, retry interval, expire interval, and minimum-related timing information.

SOA Serial Number

The SOA serial number identifies the version of the zone data. Secondary DNS servers can use it to determine whether the zone has changed and whether they need to obtain updated information from the primary source.

DNS providers may manage this value automatically, so administrators do not always need to edit it manually.

What Is a PTR Record?

A PTR, or Pointer, record performs the reverse of a typical address lookup. It maps an IP address to a hostname and is therefore associated with reverse DNS.

10.2.0.192.in-addr.arpa.  3600  IN  PTR  server.example.com.

For IPv4, reverse DNS uses the in-addr.arpa domain and reverses the order of the address components. IPv6 reverse DNS uses the ip6.arpa namespace.

Forward DNS vs Reverse DNS

LookupTypical recordQuestion
Forward DNSA or AAAAWhat IP address belongs to this hostname?
Reverse DNSPTRWhat hostname is associated with this IP address?

Reverse DNS is commonly used by mail servers, logging systems, network administration tools, and other infrastructure where an IP-to-hostname association is useful.

What Is an SRV Record?

An SRV, or Service, record specifies where a particular network service can be found. Unlike an A record, an SRV record can identify a target hostname together with a port and additional priority and weighting information.

_sip._tcp.example.com.  3600  IN  SRV  10  60  5060  sipserver.example.com.
SRV fieldMeaning
PriorityLower values have higher priority.
WeightUsed to distribute traffic among records with the same priority.
PortTCP or UDP port on which the service is available.
TargetHostname providing the service.

SRV records are used by various protocols and applications that need DNS-based service discovery, including some VoIP, messaging, directory, and collaboration systems.

What Is a CAA Record?

CAA, or Certification Authority Authorization, allows a domain owner to specify which certificate authorities are authorized to issue certificates for the domain.

example.com.  3600  IN  CAA  0 issue "ca.example.net"

CAA can help restrict certificate issuance to approved certificate authorities. Certificate authorities check applicable CAA records before issuing certificates when the relevant CA and certificate policy require it.

CAA Record Properties

PropertyPurpose
issueControls authorization for ordinary certificate issuance.
issuewildControls authorization for wildcard certificate issuance.
iodefCan specify a reporting destination for certain CAA-related events.

What Is a DNSKEY Record?

DNSKEY is a DNSSEC record containing a public key used as part of DNSSEC validation. DNSSEC adds cryptographic signatures to DNS data so resolvers can verify that authenticated DNS information has not been altered.

DNSKEY is normally encountered when working with DNSSEC rather than basic DNS configuration. Other DNSSEC record types, such as DS and RRSIG, participate in the chain of trust.

What Is a DS Record?

DS, or Delegation Signer, records connect a child DNS zone to its parent in a DNSSEC chain of trust. The DS record contains information derived from a DNSKEY and is published in the parent zone.

This allows a validating resolver to connect the cryptographic identity of a delegated child zone to the trust chain established by its parent.

What Is an RRSIG Record?

RRSIG records contain DNSSEC digital signatures for DNS record sets. A validating resolver can use the appropriate DNSKEY to verify the signature.

DNSSEC therefore introduces additional record types beyond the records normally used to direct web traffic or configure email.

What Is an ALIAS or ANAME Record?

Some DNS providers offer proprietary or standardized mechanisms with names such as ALIAS or ANAME to provide alias-like behavior where an ordinary CNAME cannot be used, particularly around zone apex names.

These are not interchangeable with a normal CNAME. Their availability and exact behavior depend on the DNS provider and the relevant DNS implementation.

DNS Records for a Typical Website

A simple website may use only a small number of DNS records. For example, the apex domain can have A and AAAA records, while www can point to the apex through a CNAME.

example.com.      3600  IN  A      192.0.2.10
example.com.      3600  IN  AAAA   2001:db8::10
www.example.com.  3600  IN  CNAME  example.com.

DNS Records for a Website With Email

Once email is added, the domain will typically need MX records pointing to the mail provider and TXT records for one or more email authentication mechanisms.

example.com.  3600  IN  MX   10 mail.example.net.
example.com.  3600  IN  TXT  "v=spf1 include:mail.example.net -all"
_dmarc.example.com.  3600  IN  TXT  "v=DMARC1; p=none"

The exact records depend on the email provider. Copying generic MX, SPF, DKIM, or DMARC examples without adapting them to the provider's documentation can break mail delivery or authentication.

DNS Records for a Subdomain

Subdomains can have their own DNS records. For example, api.example.com can point to an API server while www.example.com points to a web frontend.

api.example.com.  3600  IN  A      192.0.2.20
www.example.com.  3600  IN  CNAME  example.com.
mail.example.com. 3600  IN  A      192.0.2.30

This allows different services to use different hosts while remaining under the same parent domain.

What Does TTL Mean?

TTL, or Time to Live, tells DNS resolvers how long a record can remain cached before it should be queried again. TTL values are expressed in seconds in traditional DNS notation.

TTLEquivalent duration
3005 minutes
36001 hour
8640024 hours

A lower TTL can make DNS changes visible to resolvers sooner after their existing cached data expires, but it can also increase DNS query traffic. A higher TTL can reduce repeated queries but keeps cached information longer.

DNS Record Caching

DNS resolvers cache records according to their TTL and other DNS rules. As a result, changing a DNS record does not necessarily mean every user immediately receives the new value.

This is one reason DNS changes are often described as propagating. In reality, different recursive resolvers can have different cached states until the relevant TTLs expire.

Common DNS Configuration Mistakes

  • Using an A record when the target is actually a hostname rather than an IPv4 address.
  • Putting an IP address into a CNAME record.
  • Creating conflicting records at the same name.
  • Forgetting to create an AAAA record when IPv6 connectivity is intentionally supported.
  • Pointing an MX record to an IP address instead of a hostname.
  • Using incorrect MX priorities.
  • Publishing outdated SPF information.
  • Adding multiple SPF TXT records instead of maintaining the domain's intended SPF policy.
  • Forgetting that cached DNS data can remain available until its TTL expires.
  • Configuring DNS records at the wrong DNS provider or zone.
  • Changing authoritative name servers without understanding the resulting delegation.
  • Assuming a DNS record has propagated simply because one resolver returns the new value.

How to Check DNS Records

A DNS lookup tool can query common record types for a domain and show the values returned by a resolver. This is useful when checking whether a record exists and whether the returned value matches the intended configuration.

For example, when troubleshooting a website, you can check A and AAAA records. For email problems, inspect MX and relevant TXT records. For reverse DNS, query PTR records using the appropriate reverse lookup.

How to Check DNS Propagation

After changing a DNS record, checking the result from several DNS locations can help determine whether different recursive resolvers have updated their cached answers.

A DNS Propagation Viewer can be useful for comparing responses from different locations and identifying whether the new record value is being returned consistently.

Forward and Reverse DNS Tools

A DNS Lookup tool is useful for forward queries such as A, AAAA, MX, TXT, and other records. A Reverse DNS Lookup focuses on PTR records and answers the opposite type of question: which hostname is associated with a particular IP address.

A Whois Lookup provides a different kind of information. WHOIS data concerns domain registration and related registration records rather than ordinary DNS zone records, although both are frequently used together when investigating a domain.

DNS Record Types at a Glance

TypePrimary purposeTypical example
AIPv4 address mappingexample.com → 192.0.2.10
AAAAIPv6 address mappingexample.com → 2001:db8::10
CNAMEHostname aliaswww.example.com → example.com
MXEmail deliveryexample.com → mail.example.com
TXTText and service metadataSPF, verification, DMARC
NSAuthoritative name serversexample.com → ns1.example.net
SOAZone authority informationZone serial and timing values
PTRReverse DNSIP address → hostname
SRVService discoveryService → hostname and port
CAACertificate issuance policyAuthorized certificate authority
DNSKEYDNSSEC public keyDNSSEC validation
DSDNSSEC delegationParent-to-child trust relationship
RRSIGDNSSEC signaturesSigned DNS record set

How to Choose the Right DNS Record

The easiest way to choose a record type is to start with what you need DNS to describe. If you need to map a hostname directly to an IPv4 address, use A. For IPv6, use AAAA. If one hostname should act as an alias for another hostname, use CNAME.

For email delivery, use MX. For text-based verification or authentication policies, use TXT. For reverse IP-to-hostname mapping, use PTR. For service discovery with ports and priorities, use SRV. For certificate issuance restrictions, use CAA. DNSSEC introduces DNSKEY, DS, RRSIG, and related records.

A Practical DNS Configuration Workflow

Start by identifying which service needs to be connected to the domain. Determine whether the service gives you an IP address, a hostname, a mail server, a verification value, or a service endpoint with a port.

Choose the record type that matches that information, configure the record at the authoritative DNS provider, select an appropriate TTL, and then verify the result using DNS queries. After a change, remember that recursive resolvers can continue returning cached values until their existing TTLs expire.

For important production changes, verify both the authoritative answer and the answer seen through recursive resolvers. This makes it easier to distinguish a configuration mistake from normal DNS caching.

Frequently Asked Questions

What is the most common DNS record type?

A records are among the most common DNS records because they map hostnames to IPv4 addresses. AAAA records perform the equivalent function for IPv6.

What is the difference between A and AAAA records?

An A record maps a hostname to an IPv4 address, while an AAAA record maps a hostname to an IPv6 address. Both can exist for the same hostname.

What is the difference between CNAME and A records?

An A record contains an IPv4 address directly. A CNAME contains another hostname and makes the first name an alias of that target.

What DNS record is used for email?

MX records identify the mail servers responsible for receiving email for a domain. TXT records are also commonly used for email authentication mechanisms such as SPF, DKIM-related data, and DMARC.

What is a TXT record used for?

TXT records store text data associated with a DNS name. Common uses include domain verification, SPF, DKIM-related information, DMARC, and service-specific configuration.

What is a PTR record?

A PTR record maps an IP address to a hostname and is used for reverse DNS. IPv4 reverse DNS uses in-addr.arpa, while IPv6 reverse DNS uses ip6.arpa.

What does DNS TTL mean?

TTL specifies how long a recursive DNS resolver can cache a record before it should query for fresh data. Lower TTLs can allow changes to be observed sooner after existing caches expire, while higher TTLs generally allow longer caching.

Helpful DNS Tools

A DNS Lookup tool is useful for inspecting A, AAAA, CNAME, MX, TXT, NS, and other DNS records. A DNS Record Generator can help construct correctly formatted records for common configuration tasks. A Reverse DNS Lookup is useful when investigating PTR records and IP-to-hostname mappings, while a DNS Propagation Viewer can compare DNS responses from different locations after a configuration change. A Whois Lookup provides complementary domain registration information when DNS investigation also requires registrar or registration context.

Conclusion

DNS records are small structured pieces of configuration, but each record type has a specific role. A and AAAA connect hostnames to IP addresses, CNAME provides hostname aliases, MX controls mail-server discovery, and TXT supports many verification and authentication mechanisms.

NS and SOA records describe the authority and management of DNS zones, PTR provides reverse DNS, SRV enables service discovery, and CAA controls which certificate authorities are authorized to issue certificates. DNSSEC adds additional records such as DNSKEY, DS, and RRSIG for cryptographic validation.

When troubleshooting DNS, the most important step is to identify which record type represents the information you actually need. Once that is clear, inspecting the authoritative DNS configuration, checking cached responses, and comparing results from multiple resolvers becomes much more straightforward.

Found an issue?

Found an error, outdated information, or something missing from this article? Let me know through the Contact page.

Your feedback helps improve our articles and keep them accurate and useful.