DNSNetworkingDomainsWeb DevelopmentSecurity

DNS Records Explained: A, AAAA, MX, TXT, CNAME, NS and SOA

•By Hamid Abderrahim

Every time you open a website, send an email, or point a subdomain at a server, a DNS lookup happens first. Most developers only meet DNS when something breaks — a subdomain that will not resolve, an email that never arrives, a certificate that will not validate. Understanding DNS records turns those mysterious failures into five-minute fixes. This guide explains every major record type, how to read one, and how to debug problems with the free DNS Lookup tool.

What DNS actually does

The Domain Name System is the internet's phone book. Browsers and mail servers cannot connect to names — they need IP addresses. DNS is the distributed database that maps human-readable names (example.com) to machine-usable values (IP addresses, mail servers, verification strings).

A DNS record is one entry in that database. Each record has a type (what kind of data it holds), a name (which hostname it belongs to), a value, and a TTL (time to live, in seconds — how long other servers may cache it).

A records: names to IPv4 addresses

The A record is the workhorse: it maps a hostname to an IPv4 address such as 93.184.216.34.

example.com.    A     93.184.216.34
www.example.com.  A   93.184.216.34

Common reasons to look at A records:

  • Deployment checks — did the DNS change actually propagate?
  • Load balancing — big sites return several A records and browsers rotate between them.
  • Migration sanity checks — your old host's IP should be gone after a move.

AAAA records: the IPv6 twin

AAAA (pronounced "quad-A") does exactly what A does, but for IPv6 addresses like 2606:2800:220:1:248:1893:25c8:1946. A modern domain should have both when the hosting supports IPv6; a missing AAAA means IPv6-only visitors fall back to IPv4 (slower) or fail entirely on IPv6-only networks.

MX records: where email goes

MX (mail exchange) records tell the world which servers accept email for your domain. They carry a priority number — lower wins — so a backup mail server can take over if the primary is down.

example.com.   MX  10  smtp.google.com.
example.com.   MX  20  mail2.example.com.

If MX records are missing or stale, mail silently disappears. This is why the Email Validator tool checks live MX records before trusting an address — an address can look perfect and still be undeliverable.

TXT records: the verification workhorse

TXT records hold free-form text, and they are everywhere:

  • SPF — lists which servers may send mail as your domain.
  • DKIM — a public key that lets receivers verify signed mail.
  • DMARC — tells receivers what to do when SPF/DKIM checks fail.
  • Site verification — Google, Bing and others ask you to publish a TXT record to prove you own a domain.

A typical SPF record looks like:

example.com.  TXT  "v=spf1 include:_spf.google.com ~all"

CNAME records: aliases

A CNAME points a hostname at another hostname instead of an IP. www is the classic example:

www.example.com.  CNAME  example.com.

The lookup then continues at the target. Two rules trip people up:

  1. A CNAME cannot coexist with other records on the same name. The apex (example.com itself) must use A/AAAA records or a provider-specific ALIAS/ANAME feature.
  2. Chains cost time. Every hop is another lookup; keep chains short.

NS records: who is authoritative

NS (name server) records delegate a domain — or a subdomain — to a set of authoritative DNS servers. If your NS records still point at a host you migrated away from, changes you make "do nothing" because the world is asking the wrong servers. After a registrar change, verify NS records first.

SOA records: the metadata card

Every zone starts with an SOA (start of authority) record holding the admin email, a serial number, and cache timers (refresh, retry, expire, negative TTL). You rarely edit it by hand, but it is the first thing support engineers read when diagnosing replication problems.

A real debugging checklist

When a domain misbehaves, walk through in this order:

  1. Does the name resolve at all? Look up the A/AAAA records.
  2. Are the answers current? Compare TTLs; recent edits may still be cached.
  3. Who is authoritative? Check NS records — are they the provider you think?
  4. Email broken? Verify MX, SPF and DKIM TXT records.
  5. CNAME conflicts? Make sure no other record sits on an aliased name.

You can run every one of these checks on any domain with the DNS Lookup tool — it queries A, AAAA, MX, TXT, NS, SOA, CNAME records and can sweep all of them in one request, right from your browser.

Frequently asked questions

How long do DNS changes take?

TTL governs it. Records with a 3600-second TTL can be cached for up to an hour. Lower the TTL before a planned migration, then raise it again afterwards.

Can a domain have multiple A records?

Yes — and it is a simple, effective form of load balancing. Clients typically try the first address and fall back to the others.

Why does my mail fail when the website works?

Mail and web traffic use different records. Working A records say nothing about MX records, SPF or DKIM. Check the mail side separately.

What is the difference between CNAME and A record?

An A record answers with an IP address directly. A CNAME answers with another name that must then be resolved — useful for aliases, but never allowed on the zone apex.


Try it yourself: inspect any domain's full DNS profile with DNS Lookup, and confirm a mail server is behaving with Network Ping — both run entirely in your browser, free.