DNS record types explained
Kort antwoord
A DNS zone is a set of records that tell the internet where to find things for your domain. The ones you'll meet most often are A and AAAA (point a name at an IPv4 or IPv6 address), CNAME (alias one name to another), MX (route mail), TXT (arbitrary text, often used for verification and email authentication), NS (delegate the zone) and CAA (control which certificate authorities can issue for the domain).
How a DNS lookup resolves
When something asks "what's the IP address for example.com", that question usually goes to a recursive resolver, often run by an ISP or a public service. The resolver doesn't necessarily know the answer itself, so it works up a chain: it asks a root server which server handles the .com top-level domain, then asks that TLD server which name server is authoritative for example.com, then finally asks that authoritative name server for the actual record. The answer gets cached along the way so the same lookup doesn't have to repeat the whole chain every time, which is why DNS changes take a while to be visible everywhere: caches at each step hold onto the old answer until it expires.
The record types you'll actually use
| Record | What it does | Typical use |
|---|---|---|
| A | Points a name at an IPv4 address | Pointing a domain or subdomain at a server |
| AAAA | Points a name at an IPv6 address | Same as A, for IPv6 |
| CNAME | Aliases one name to another name, which is then resolved in turn | Pointing www at a root domain, or a subdomain at a third-party service |
| MX | Routes mail for the domain to a mail server, with a priority value | Telling other mail servers where to deliver mail for your domain |
| TXT | Holds arbitrary text | Domain ownership verification, and email authentication (SPF, DKIM, DMARC) |
| NS | Delegates a zone to the name servers responsible for it | Telling the rest of DNS which servers answer for your domain |
| CAA | Specifies which certificate authorities are allowed to issue certificates for the domain | Restricting who can issue a TLS certificate for your name |
A, AAAA and CNAME: pointing a name somewhere
A and AAAA records are the most direct kind of DNS record: a name on one side, an IP address on the other. A points at an IPv4 address, AAAA at an IPv6 address, and a domain commonly has both so it's reachable over either protocol. See IPv4 vs. IPv6: do you actually need extra IPv4 addresses for the difference between the two address families themselves.
CNAME works differently: instead of pointing at an address, it points at another name, which is then resolved as its own lookup. This is useful when the target might change, or is managed by someone else, such as pointing a subdomain at a service hosted elsewhere. A CNAME can't coexist with other records on the same name, which is the main practical limit to be aware of.
MX: routing mail
MX records tell other mail servers where to deliver mail addressed to your domain. Each MX record has a priority value, lower numbers are preferred, so a domain can list a primary mail server and one or more fallbacks. Without an MX record, mail sent to the domain generally has nowhere to go.
TXT: verification and email authentication
A TXT record just holds text, and DNS doesn't care what that text says, which is why it gets reused for so many purposes. The two most common are proving you control a domain (a service asks you to add a specific TXT value, then checks it's there) and email authentication, where SPF, DKIM and DMARC are all published as TXT records. See Email authentication: SPF, DKIM and DMARC explained for what those three actually do.
NS: delegating the zone
NS records are how DNS itself finds out which name servers are authoritative for a domain. They usually live in two places: at the registry (so the chain from the TLD down knows where to send lookups) and inside the zone itself. Getting NS records wrong at the registry is one of the more disruptive DNS mistakes, since it can make the whole domain unreachable rather than just one record.
CAA: controlling who can issue a certificate
CAA records are a narrower, more recent addition: they let a domain owner specify which certificate authorities are permitted to issue a TLS certificate for that domain. A CA is supposed to check for a CAA record before issuing, and refuse if the record doesn't list them. It's not a replacement for anything else in this list, but it closes a gap: without it, in principle any public CA could be asked to issue a certificate for your name.
Reverse DNS: the lookup in the other direction
Everything above resolves a name to an address. Reverse DNS does the opposite: given an IP address, it answers with a name. It's a separate record type (a PTR record) managed separately from the forward A/AAAA record, and it matters most for things like outbound mail servers, where receiving mail servers often check that the sending IP has a sensible reverse DNS entry. See How to edit reverse DNS (rDNS) for adjusting this on a Worldstream IP.