DNS explained
DNS in plain language
You don’t need to be an engineer to set up your domain. Here’s what the words mean.
- DNS
- The internet’s address book: it turns names like example.com into the addresses computers use.
- The Domain Name System (DNS) is how the internet finds things. When someone visits your website or sends you email, their computer asks DNS where to go. You control your domain’s answers by editing its DNS records at your DNS provider.
- DNS record
- One line of instructions in your domain’s DNS, such as “email goes to Google”.
- A DNS record has a name (which part of your domain it applies to), a type (what kind of instruction it is, like A or MX) and a value (where to point). Most services you connect to your domain give you a few records to add.
- A record
- Points a name to the IPv4 address of a server, usually your website.
- An A record connects a name (like example.com) to a numeric IPv4 address (like 76.76.21.21). Website builders and hosts often ask you to add one for your root domain.
- AAAA record
- Like an A record, but for newer IPv6 addresses.
- AAAA (“quad A”) records work exactly like A records but hold IPv6 addresses, which look like 2606:50c0:8000::153. They’re optional unless your host asks for them.
- CNAME record
- Makes a name an alias of another name, so it follows wherever that name points.
- A CNAME says “this name is the same as that other name”. It’s commonly used for www and for connecting a subdomain to a service (e.g. app.example.com → customers.yoursaas.com). A name that has a CNAME can’t have any other records, which is why it can’t normally be used on your root domain.
- MX record
- Tells the world which servers receive email for your domain.
- MX (mail exchange) records list the servers that accept email for your domain, each with a priority number — lower numbers are tried first. If you switch email providers, you replace your MX records.
- TXT record
- A free-form text note, used to prove you own a domain and for email security.
- TXT records hold text. Services ask you to add one to verify that you own the domain, and email security settings (SPF, DKIM, DMARC) are also stored as TXT records. A name can have several TXT records.
- Nameservers (NS)
- The company that hosts your DNS. This is where you add and change records.
- Nameservers are the servers that hold your domain’s DNS records. They’re usually run by your registrar (like GoDaddy or Namecheap) or a DNS service (like Cloudflare). To change a record, log in to whichever company your nameservers belong to.
- CAA record
- Limits which companies may issue HTTPS certificates for your domain.
- Certification Authority Authorization (CAA) records list the certificate authorities (like Let’s Encrypt) allowed to issue certificates for your domain. It’s an optional extra layer of protection against mis-issued certificates.
- SPF
- A list of the services allowed to send email as your domain.
- SPF (Sender Policy Framework) is a TXT record starting with “v=spf1”. It lists who may send email on your behalf — for example Google Workspace and your newsletter tool. You must have only one SPF record; if you use several services, combine them into one.
- DKIM
- A digital signature that proves an email really came from your domain.
- DKIM (DomainKeys Identified Mail) adds a signature to your outgoing email. The public key is published in DNS, usually as a TXT or CNAME record at a name like google._domainkey. Your email provider generates the value for you.
- DMARC
- Tells other mail servers what to do with email that fails SPF/DKIM checks.
- DMARC is a TXT record at _dmarc.yourdomain. Its policy can be “none” (just report), “quarantine” (send to spam) or “reject” (block). Start with “none” to collect reports, then tighten it once your legitimate email passes.
- DNSSEC
- Cryptographic signatures that stop attackers from faking your DNS answers.
- DNSSEC signs your DNS records so resolvers can check they haven’t been tampered with. It’s optional and usually enabled with one click at your DNS provider plus a DS record at your registrar. A half-finished setup can make your domain unreachable, so follow your provider’s guide.
- TTL (time to live)
- How long (in seconds) other servers may remember a record before asking again.
- TTL controls caching. A TTL of 3600 means resolvers can keep using the old answer for up to an hour after you change a record. Lower TTLs make changes spread faster; higher TTLs mean fewer lookups.
- Propagation
- The time it takes for a DNS change to be seen everywhere.
- DNS changes are usually live at your provider within seconds, but resolvers around the world may keep the old answer until its TTL runs out. That delay is called propagation. It’s typically minutes to a few hours.
- Root domain (apex)
- Your domain without anything in front, like example.com. Usually written as “@”.
- The root or apex domain is the bare domain you registered. In most DNS dashboards you refer to it as “@” (or leave the name field empty). CNAME records aren’t allowed here, so services give you A records or an ALIAS/flattening option instead.
- Subdomain
- A name in front of your domain, like www.example.com or app.example.com.
- Subdomains let you point different parts of your domain to different services. In your DNS dashboard you usually type only the part in front (for app.example.com, type “app”).
- Name / Host field
- The box in your DNS dashboard where you say which name a record applies to.
- Most providers automatically add your domain to whatever you type. So for app.example.com you type just “app”. Typing the full name often creates app.example.com.example.com by mistake — one of the most common DNS errors.
- Resolver
- The DNS server your device asks for answers, like Google’s 8.8.8.8 or Cloudflare’s 1.1.1.1.
- Resolvers look up and cache DNS answers on behalf of people’s devices. Because each one caches separately, different resolvers can briefly give different answers after a change.
- Proxied (orange cloud)
- Cloudflare hides your real record behind its own servers.
- When a record is “proxied” in Cloudflare (orange cloud), DNS shows Cloudflare’s addresses instead of your value. Many services can’t verify a proxied record, so set it to “DNS only” (grey cloud) when a setup guide asks you to.
- NXDOMAIN
- The DNS answer for “this name doesn’t exist”.
- NXDOMAIN means no records exist at that name at all. For a whole domain, it usually means it isn’t registered, has expired, or its nameservers aren’t set up.