Networking
DNS records explained for self-hosters: A, AAAA, CNAME, MX, TXT and more
What each DNS record type does, how to point a domain at your server, why TTL matters, how to set up email records, and commands to check what the world sees.
By Raktim Ranjit · Published · 3 min read
Short answer: DNS turns names into addresses and other facts. For a self-hosted site you mostly need an A record (name to IPv4 address), an AAAA record (IPv6), a CNAME (alias to another name), MX and TXT records for email, and CAA to limit who can issue certificates. Changes are not instant because resolvers cache answers for the record's TTL.
What are the main record types?
- A: maps a name to an IPv4 address.
app.example.com A 203.0.113.10. - AAAA: the same for an IPv6 address.
- CNAME: makes one name an alias of another.
www.example.com CNAME example.com. A name with a CNAME cannot have other records, which is why you cannot put a CNAME at the root of the domain on a standard DNS provider. - MX: names the mail servers for the domain, each with a priority number. Lower is tried first.
- TXT: free text, used for domain verification and email authentication (SPF, DKIM, DMARC).
- NS: the name servers that are authoritative for the domain. Set at the registrar.
- CAA: lists which certificate authorities may issue for the domain.
- SRV: service location with port, used by some protocols.
- PTR: reverse lookup from IP to name, set by whoever owns the IP, which is your hosting provider. Important for mail.
How do you point a domain at your server?
example.com. A 203.0.113.10
www.example.com. CNAME example.com.
app.example.com. A 203.0.113.10
example.com. AAAA 2001:db8::10Use one entry per service name, all pointing at your reverse proxy's address, and let the proxy route by hostname. A wildcard record *.example.com A ... sends every subdomain to the same place, which is convenient and exposes names you may not want.
What is TTL?
Time to live, in seconds, tells resolvers how long they may cache the answer. A TTL of 3600 means up to an hour before everyone sees a change. Before a planned move, lower the TTL to 300 a day ahead, make the change, then raise it again. If you forget, some users reach the old server for hours.
What do you need for email?
If you send mail from your domain, receivers check three TXT records.
example.com. TXT "v=spf1 include:_spf.mailprovider.com -all"
selector._domainkey.example.com TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."
_dmarc.example.com. TXT "v=DMARC1; p=quarantine; rua=mailto:[email protected]"- SPF lists the servers allowed to send for your domain. Only one SPF record per domain.
- DKIM publishes a public key; your mail server signs messages with the private one.
- DMARC tells receivers what to do when SPF and DKIM fail, and where to send reports.
Without these, your business emails go to spam or are rejected. Use a reputable mail provider for sending, since hosting mail yourself is a hard problem.
How do you check what DNS says?
dig +short A app.example.com
dig +short MX example.com
dig +short TXT example.com
dig @1.1.1.1 app.example.com # ask a specific resolver
dig +trace app.example.com # follow the chain from the root
whois example.com # registrar and name serversIf your answer is right on one resolver and wrong on another, you are waiting for cache expiry.
What breaks DNS most often?
- A CNAME at the zone root, or alongside other records.
- Forgetting the AAAA record is old. If you have an IPv6 record pointing at a server that doesn't listen on IPv6, some visitors fail while you see nothing wrong.
- A trailing dot confusion in zone files.
- Two SPF records.
- Expired domain registration. Turn on auto-renew.
- Changing name servers without copying all records first.
Certificate issuance depends on DNS too. See certificate renewal for the DNS challenge.
References
Author
Raktim Ranjit is a software engineer and the founder of NodeDR Infotech. He builds and maintains the software described here.