Understanding DNS Records: A Field Guide for Site Owners
By ABD Web Tools Editorial · 2026-03-02 · 9 min read
DNS is the part of the stack most site owners touch twice a year and fear every time. The mental model is simpler than the interface suggests: DNS is a distributed lookup table that turns names into answers, and each record type answers a different question about your domain.
The record types you will actually use
Seven types cover almost every real situation:
- A — points a name to an IPv4 address.
- AAAA — the same for IPv6.
- CNAME — points a name at another name, useful for platform-hosted sites.
- MX — tells the world which servers receive your email.
- TXT — free-form text used for domain verification, SPF and DKIM.
- NS — delegates the domain to a set of nameservers.
- CAA — restricts which certificate authorities may issue certificates for you.
The apex-CNAME problem
The specification does not allow a CNAME at the root of a domain, because the root also needs NS and SOA records. Providers work around this with ALIAS or ANAME records that behave like a CNAME but resolve server-side. If your host offers one, use it; otherwise point the apex at an A record and use a CNAME for the www subdomain.
Advertisement
TTL and what propagation really means
There is no global broadcast. Each resolver caches an answer for the number of seconds given in the record's time-to-live, then asks again. 'Propagation' is simply the slowest cache expiring.
The practical consequence: lower the TTL to 300 seconds at least a day before a planned migration, make the change, confirm it, then raise the TTL back to an hour or more. Doing it in the other order guarantees a long tail of stale answers.
Email records, briefly
SPF lists who may send mail as your domain and lives in a TXT record; you may have only one SPF record. DKIM publishes a public key so receivers can verify signatures. DMARC tells receivers what to do when SPF or DKIM fails and where to send reports. Configure all three, start DMARC in monitoring mode, and only tighten the policy once the reports look clean.
Debugging a domain that stopped working
Work outward in this order and you will find the fault quickly:
- Confirm the domain has not expired at the registrar.
- Check that the NS records point at the nameservers you are editing — editing the wrong zone is the classic mistake.
- Query the authoritative nameserver directly rather than your local resolver.
- Compare answers from a public resolver to rule out local caching.
- Verify the certificate matches the hostname if the site loads but warns.
Sensible defaults for a new domain
Apex A record and www CNAME, MX records from your mail provider, SPF plus DKIM plus a monitoring DMARC record, a CAA record naming your certificate authority, and a TTL of one hour once everything is stable. Record the setup somewhere your team can find it — most DNS emergencies are archaeology problems.
Frequently asked questions
How long does a DNS change take?
Between a few seconds and the previous record's TTL, plus any extra caching by intermediate resolvers. Planning for a few hours is realistic; 48 hours is a legacy figure.
Can I have two SPF records?
No. Multiple SPF records cause validation to fail. Merge all senders into a single record.
Should I use my registrar's DNS or a third party?
Either works. A dedicated DNS provider usually offers faster resolution, better APIs and finer TTL control.
What is a CAA record for?
It limits which certificate authorities can issue certificates for your domain, reducing the risk of mis-issuance.
Advertisement