Mist Network

DNS Record Types Explained: A, AAAA, CNAME, MX, TXT and More

A practical guide to the DNS record types you will actually use, from A and MX to CAA, HTTPS and DS, with example values, TTL advice and the mistakes that break websites and email.

Updated: 6 min read
DNS record types explained: a DNS zone table listing A, AAAA, CNAME, MX and TXT records

DNS record types are the different kinds of entries in a domain's DNS zone, each telling the internet one specific thing. An A record maps a name to an IPv4 address, AAAA to IPv6, CNAME makes one name an alias of another, MX routes email, TXT holds verification and email-security text, and NS names the servers that answer for the zone.

Those six cover most everyday needs. The rest handle security, services and newer protocols. This guide walks through all 20 types you can create in a modern DNS panel, with example values and the mistakes we see most often.

Anatomy of a DNS record

Every record has the same four parts, whatever its type:

  • Name — the host the record applies to, such as @ (the root, or apex, of the domain), www or mail.
  • Type — A, MX, TXT and so on. The type decides how the value is interpreted.
  • TTL — time to live, in seconds. It tells resolvers how long they may cache the answer.
  • Value — the data itself: an IP address, a hostname, a text string or a structured set of fields.
example.com.      3600  IN  A      203.0.113.10
www.example.com.  3600  IN  CNAME  example.com.
example.com.      3600  IN  MX     10 mail.example.com.

The format goes back to RFC 1035, and it still shapes how every DNS panel works today, even when the panel hides the zone file behind a form.

The core records every domain uses

TypeWhat it doesExample value
APoints a name to an IPv4 address203.0.113.10
AAAAPoints a name to an IPv6 address2001:db8::10
CNAMEMakes a name an alias of another hostnameexample.com.
MXNames the mail servers for the domain, with a priority10 mail.example.com.
TXTFree text: SPF, DKIM, DMARC, ownership verificationv=spf1 mx -all
NSDelegates the zone or a subdomain to nameserversns1.provider.net.

A and AAAA: where your site lives

If your website runs on a VPS, the A record for @ carries the server's IPv4 address. Add an AAAA record only if the server really answers on IPv6; a stale AAAA record sends IPv6 visitors to nowhere while IPv4 users see a working site, which is a confusing bug to debug. The full walkthrough is in our guide on how to point a domain to a VPS.

CNAME: aliases, with strict rules

A CNAME says "this name is the same as that name". It is perfect for www, for shop pointing at a hosted store, or for verification hostnames. Two rules trip people up. A name with a CNAME cannot carry any other record, so you cannot put a classic CNAME on the apex, which already holds NS and usually MX records. And MX or NS records should point to hostnames with A or AAAA records, never to a CNAME.

MX and TXT: email that actually arrives

MX records list mail servers with a priority number; lower numbers are tried first. TXT records then prove the mail is legitimate. SPF (v=spf1 …) lists who may send for your domain, DKIM publishes a signing key under a selector such as s1._domainkey, and DMARC (_dmarc) tells receivers what to do when checks fail. Keep exactly one SPF record per name; two SPF TXT records make the check fail.

NS: who answers for the zone

NS records live in two places, and that split causes a lot of confusion. The first is the delegation held at the registry for your extension; when you change a domain's nameservers, this is what you are updating. The second is the set of NS records inside the zone itself, which should match the delegation. To hand a subdomain such as dev.example.com to a different DNS provider, you add separate NS records for that name. The rule is simple: whichever nameservers appear in the delegation give the real answers, and edits made anywhere else stay invisible to the world.

Security and trust records

These records do not route traffic. They tell clients what to trust.

  • CAA — lists the certificate authorities allowed to issue TLS certificates for your domain, for example 0 issue "letsencrypt.org". A wrong CAA record silently blocks certificate renewals.
  • DS and DNSKEY — the DNSSEC chain of trust. DNSKEY holds the zone's public keys; the DS record, published at the parent registry, vouches for them.
  • TLSA — DANE: pins the certificate or key a TLS service should present, used mostly by mail servers.
  • SSHFP — publishes SSH host-key fingerprints so clients can verify a server on first connection.
  • SMIMEA — associates S/MIME certificates with email addresses.
  • CERT — stores certificates or pointers to them; rarely used, but still supported.
Tip: Add a CAA record as soon as you know which certificate authority you use. It is two minutes of work and closes off a whole class of mis-issuance problems.

Service, discovery and specialist records

TypeTypical use
SRVLocates a service by protocol and port, e.g. _sip._tcp, XMPP, some game servers
HTTPS / SVCBAdvertise HTTP/3 support, alternative endpoints and connection hints so browsers connect faster
URIMaps a service name to a URI
NAPTRRewrite rules used in telephony (ENUM, SIP)
PTRReverse DNS: maps an IP address back to a name
LOCPublishes geographic coordinates for a host

One note on PTR: reverse DNS for a server's IP lives in the reverse zone controlled by whoever owns the IP block, usually your hosting provider. Adding a PTR record inside your own domain's zone does not change what a mail server sees when it checks your VPS address.

TTL: how long answers are cached

TTL is the most underrated field in a DNS record. A long TTL (for example 86400 seconds, one day) reduces lookups and keeps answers stable. A short TTL (60 to 300 seconds) lets changes reach users quickly. The practical pattern: lower the TTL a day before a planned migration, make the change, confirm it works, then raise it again.

Resolvers that cached the old answer keep it until its TTL runs out, which is most of what people call DNS propagation.

Common DNS mistakes to avoid

Watch out for these: a CNAME on the apex or next to other records; two SPF TXT records on the same name; MX pointing to a CNAME or to an IP address; leftover AAAA records after a server move; a CAA record that excludes the CA you actually use; and hostnames entered without understanding whether the panel appends the domain automatically.

When something breaks, check the record that clients actually receive with a lookup tool or dig, not just what the panel shows. If the answer differs, either the TTL has not expired yet or the domain is using different nameservers than you think. A practical order of checks: find out which nameservers the domain is delegated to, query one of them directly, and compare the answer with what you entered in the panel. If they match, the record is fine and you are only waiting for caches to expire.

Managing DNS records at mistREG

20record types supported
60–86400 sselectable TTL, or auto
200+TLDs to register

Domains registered at mistREG get their DNS zone hosted on Cloudflare's authoritative DNS network, managed from the mistREG panel. All 20 types covered above are available: A, AAAA, CNAME, MX, TXT, NS, SRV, CAA, PTR, HTTPS, SVCB, URI, TLSA, SMIMEA, SSHFP, DS, DNSKEY, CERT, NAPTR and LOC, with TTL from 60 to 86400 seconds or auto. Records are DNS-only, meaning Cloudflare answers the queries but does not proxy your website traffic. If you prefer another provider, you can set custom nameservers instead, and the domain then leaves the hosted zone. We compare both approaches in Cloudflare DNS vs registrar DNS.

  1. Register or move your domain — search 200+ extensions in the domain search.
  2. Open the DNS section in the panel — the zone is created for you on Cloudflare's network.
  3. Add your records — typically A for @, CNAME for www, MX and TXT for email, CAA for certificates.
  4. Pick a TTL — short while you are testing, longer once things are stable.

Need a server for those A records? mistREG's KVM VPS in Slovenia is ready within about 60 seconds of payment; see the plans. Questions go to support on Telegram at @mistnetwork or through the ticket system, and the FAQ covers the basics. Use your domain and DNS for legitimate projects; the provider's terms apply.

Frequently asked questions

What are the most common DNS record types?
A, AAAA, CNAME, MX, TXT and NS. A and AAAA point names to IPv4 and IPv6 addresses, CNAME creates aliases, MX routes email, TXT holds SPF, DKIM, DMARC and verification strings, and NS delegates the zone to nameservers.
What is the difference between an A record and a CNAME?
An A record points a name directly to an IPv4 address. A CNAME points a name to another hostname, which is then resolved to an address. A name with a CNAME cannot have any other records, so the apex of a domain normally uses A and AAAA records.
Can I have multiple MX records?
Yes. Each MX record has a priority number, and sending servers try the lowest number first, falling back to higher ones if it is unreachable. Equal priorities share the load.
What TTL should I use for DNS records?
For stable records, 3600 seconds (one hour) or more is fine. Before a planned change, lower the TTL to 60–300 seconds a day in advance so the new value spreads quickly, then raise it again afterwards.
What is a CAA record used for?
A CAA record lists the certificate authorities allowed to issue TLS certificates for your domain. It reduces the risk of mis-issued certificates, but a wrong value will block your own renewals, so keep it in sync with the CA you use.
Why does my DNS change not show up yet?
Resolvers keep cached answers until the old record's TTL expires. Check that you edited the zone on the nameservers the domain actually uses, then wait out the previous TTL.

Related articles

Mist NetworkMist Network