DNS record types explained
| Record | What it does |
|---|---|
A | Points the domain to an IPv4 address |
AAAA | Points the domain to an IPv6 address |
MX | Mail servers that receive email for the domain |
TXT | Free text - used for SPF, domain verification and more |
NS | Name servers that are authoritative for the domain |
CNAME | Alias that points one name to another name |
SOA | Start of authority - primary server and zone serial |
CAA | Certificate authorities allowed to issue SSL certificates |
DNS records that protect your domain
- SPF (TXT) lists the servers allowed to send email for your domain.
- DMARC (TXT on
_dmarc) tells receivers what to do with mail that fails SPF or DKIM. - CAA limits which companies can issue certificates for you.
Missing SPF and DMARC make it easy for scammers to send email pretending to be you. Check the full picture with the Email Header Analyzer and the SSL Checker.
Frequently asked questions
What is a DNS lookup?
DNS translates a domain name like example.com into the IP addresses and settings computers use. A DNS lookup asks the internet's DNS servers which records a domain has right now.
Which DNS server does this tool use?
Queries go from your browser to Google Public DNS over HTTPS, so you see what most of the internet sees. Results can differ briefly from your own provider while changes propagate.
How long does DNS propagation take?
Each record has a TTL (time to live) in seconds. Resolvers may keep the old value until the TTL expires - usually 5 minutes to 24 hours. Lower the TTL a day before planned changes.
How do I check SPF and DMARC records?
Choose TXT for the domain to see its SPF record (starts with v=spf1). For DMARC, look up TXT records of _dmarc.yourdomain.com. The "All records" mode checks DMARC for you.
What is a CAA record?
A CAA record lists which certificate authorities may issue SSL certificates for the domain. It is a simple way to stop attackers from getting certificates from other providers.