Skip to content
Back to Blog
DNS & Networking11 min read

DNS Record Types: The Complete Checklist & Setup Guide (2026)

A step-by-step walkthrough of every major DNS record type—A, AAAA, CNAME, MX, TXT, NS, SOA, SRV, CAA, and more—with practical setup commands and real-world configuration examples.

Written by Abdul AbrorTechnical Hosting Support Engineer
DNS Record Types: The Complete Checklist & Setup Guide (2026)
On this page

Setting up DNS records correctly is foundational to hosting websites, routing email, and running services. This guide walks you through every major DNS record type with numbered steps, example configurations, and practical commands you can run today.

Prerequisites: What You Need Before You Start

Before configuring DNS records, ensure you have:

  1. Domain name ownership – registered with any registrar
  2. Access to DNS management – via your registrar, hosting control panel (cPanel, Plesk), or dedicated DNS provider (Cloudflare, Route 53)
  3. Target IP addresses or hostnames – know where your records should point
  4. SSH or control panel access – if you're managing your own nameserver

Step 1: Understand Your DNS Zone Structure

Every domain has a DNS zone containing all its records. The zone is managed by authoritative nameservers (listed in NS records).

Check Your Current Nameservers

Run this command to see which nameservers currently host your domain's zone:

dig +short NS example.com

Or:

nslookup -type=NS example.com

The output shows your authoritative nameservers. All DNS changes must be made on those servers.

Step 2: Set Up A Records (IPv4 Addresses)

An A record maps a hostname to an IPv4 address. This is the most common record type.

When to Use A Records

  • Point your domain root (example.com) to a web server
  • Map subdomains (www.example.com, blog.example.com) to specific IPs
  • Direct traffic to any IPv4-based service

Configuration Steps

Via cPanel DNS Zone Editor:

  1. Log into cPanel
  2. Navigate to Zone Editor under Domains
  3. Click Manage next to your domain
  4. Click + A Record
  5. Enter: - Name: @ (for root domain) or subdomain like www - TTL: 14400 (4 hours) or 3600 (1 hour) - Address: Your server's IPv4 (e.g., 203.0.113.50)
  6. Click Add Record

Via BIND Zone File:

@       IN  A       203.0.113.50
www     IN  A       203.0.113.50
blog    IN  A       203.0.113.75

Verify:

dig +short A example.com

You should see your configured IPv4 address.

Step 3: Set Up AAAA Records (IPv6 Addresses)

An AAAA record ("quad-A") maps a hostname to an IPv6 address.

When to Use AAAA Records

  • Your server has IPv6 connectivity
  • You want to serve traffic over IPv6
  • Modern best practice for dual-stack hosting

Configuration Steps

Via cPanel:

  1. Zone Editor → Manage → + AAAA Record
  2. Enter: - Name: @ or subdomain - IPv6 Address: 2001:db8::1 (your actual IPv6) - TTL: 14400
  3. Add Record

Via Zone File:

@       IN  AAAA    2001:db8::1
www     IN  AAAA    2001:db8::1

Verify:

dig +short AAAA example.com

Step 4: Set Up CNAME Records (Aliases)

A CNAME record creates an alias that points one hostname to another.

When to Use CNAME Records

  • Point www.example.com to example.com
  • Route subdomains to external services (CDN, email platform)
  • Never use CNAME at the domain root (technical restriction)

Configuration Steps

Via cPanel:

  1. Zone Editor → + CNAME Record
  2. Enter: - Name: www or subdomain - CNAME: example.com. (note the trailing dot) - TTL: 14400
  3. Add Record

Via Zone File:

www     IN  CNAME   example.com.
shop    IN  CNAME   shops.shopify.com.

Verify:

dig +short CNAME www.example.com

Common Pitfall

CNAME records cannot coexist with other record types for the same hostname. If www has a CNAME, it cannot also have an A, MX, or TXT record.

Step 5: Set Up MX Records (Mail Routing)

An MX record directs email to your mail servers. Priority values determine routing order (lower number = higher priority).

When to Use MX Records

  • Configure email delivery for your domain
  • Route mail through Google Workspace, Microsoft 365, or your own mail server

Configuration Steps

Via cPanel:

  1. Zone Editor → + MX Record
  2. Enter: - Priority: 10 (primary server), 20 (backup) - Destination: mail.example.com. or external mail server - TTL: 14400
  3. Add Record

Example for Google Workspace:

@   IN  MX  1   aspmx.l.google.com.
@   IN  MX  5   alt1.aspmx.l.google.com.
@   IN  MX  5   alt2.aspmx.l.google.com.
@   IN  MX  10  alt3.aspmx.l.google.com.
@   IN  MX  10  alt4.aspmx.l.google.com.

For Your Own Mail Server:

@   IN  MX  10  mail.example.com.
@   IN  MX  20  mail2.example.com.

Ensure the mail server hostnames have corresponding A or AAAA records.

Verify:

dig +short MX example.com

Step 6: Set Up TXT Records (Verification & Policy)

A TXT record holds arbitrary text data. Common uses include SPF, DKIM, DMARC, and domain verification.

When to Use TXT Records

  • SPF: authorize sending mail servers
  • DKIM: cryptographic email authentication
  • DMARC: email policy and reporting
  • Domain verification (Google, Microsoft, SSL providers)

Configuration Steps

SPF Record Example:

@   IN  TXT "v=spf1 mx include:_spf.google.com ~all"

DKIM Record Example:

default._domainkey  IN  TXT "v=DKIM1; k=rsa; p=MIGfMA0GCS..."

DMARC Record Example:

_dmarc  IN  TXT "v=DMARC1; p=quarantine; rua=mailto:[email protected]"

Domain Verification Example:

@   IN  TXT "google-site-verification=abc123xyz"

Via cPanel:

  1. Zone Editor → + TXT Record
  2. Enter: - Name: @, _dmarc, or specific subdomain - TXT Data: Your policy string in quotes - TTL: 14400
  3. Add Record

Verify:

dig +short TXT example.com
dig +short TXT _dmarc.example.com

Step 7: Set Up NS Records (Nameserver Delegation)

An NS record delegates a zone or subdomain to specific nameservers.

When to Use NS Records

  • Delegate a subdomain to another DNS provider
  • Point your domain to external nameservers (Cloudflare, AWS Route 53)

Configuration Steps

NS records for the domain root are typically managed at your registrar, not in the zone itself.

Subdomain Delegation Example:

shop    IN  NS  ns1.shopify.com.
shop    IN  NS  ns2.shopify.com.

This delegates all DNS queries for shop.example.com to Shopify's nameservers.

At Registrar (for root domain):

  1. Log into your domain registrar
  2. Find Nameserver or DNS settings
  3. Enter your chosen nameservers: - ns1.example.com - ns2.example.com - Or external: ns1.cloudflare.com, ns2.cloudflare.com
  4. Save changes

Verify:

dig +short NS example.com

Step 8: Set Up SOA Record (Zone Authority)

The SOA (Start of Authority) record defines the authoritative nameserver and zone parameters.

When to Use SOA Records

You typically don't manually create SOA records—your DNS server generates them automatically. However, understanding them is essential for troubleshooting.

SOA Record Structure

example.com.  IN  SOA  ns1.example.com. admin.example.com. (
    2026071101  ; Serial (YYYYMMDDnn)
    7200        ; Refresh
    3600        ; Retry
    1209600     ; Expire
    86400       ; Minimum TTL
)

Parameters Explained:

  • Serial: Increment this when you change the zone (triggers secondary server updates)
  • Refresh: How often secondary servers check for updates
  • Retry: Wait time if refresh fails
  • Expire: When secondary servers discard data if primary is unreachable
  • Minimum TTL: Default TTL for negative responses

Verify:

dig SOA example.com

Step 9: Set Up SRV Records (Service Discovery)

An SRV record specifies the location of services (host and port).

When to Use SRV Records

  • Configure Microsoft services (SIP, Office 365)
  • XMPP/Jabber chat servers
  • LDAP directory services
  • Game servers and VoIP

Configuration Steps

Format:

_service._protocol.name  TTL  IN  SRV  priority weight port target

Example for SIP:

_sip._tcp   IN  SRV  10  60  5060  sipserver.example.com.

Example for Minecraft:

_minecraft._tcp  IN  SRV  0  5  25565  mc.example.com.

Via cPanel:

  1. Zone Editor → + SRV Record
  2. Enter: - Service: _sip - Protocol: _tcp - Priority: 10 - Weight: 60 - Port: 5060 - Target: sipserver.example.com.
  3. Add Record

Verify:

dig +short SRV _sip._tcp.example.com

Step 10: Set Up CAA Records (Certificate Authority Authorization)

A CAA record restricts which certificate authorities can issue SSL/TLS certificates for your domain.

When to Use CAA Records

  • Prevent unauthorized SSL certificate issuance
  • Required by some compliance frameworks
  • Increase domain security posture

Configuration Steps

Allow Let's Encrypt:

example.com.  IN  CAA  0 issue "letsencrypt.org"

Allow DigiCert and report violations:

example.com.  IN  CAA  0 issue "digicert.com"
example.com.  IN  CAA  0 iodef "mailto:[email protected]"

Forbid all issuance:

example.com.  IN  CAA  0 issue ";"

Via cPanel:

  1. Zone Editor → + CAA Record
  2. Enter: - Tag: issue - Value: letsencrypt.org
  3. Add Record

Verify:

dig +short CAA example.com

Step 11: Set TTL Values Strategically

TTL (Time To Live) determines how long resolvers cache your DNS records.

Recommended TTL Values

  • Before migration: Lower to 300 (5 minutes) for quick rollback
  • After migration: Raise to 3600 (1 hour) or 14400 (4 hours)
  • Stable records: Use 86400 (24 hours)
  • MX and NS records: Keep at 14400 or higher

How to Update TTL

Most DNS interfaces let you specify TTL per record. Lower values increase query load but allow faster changes. Higher values reduce DNS traffic and improve performance.

Step 12: Verify All Records

After configuration, verify every record:

# Check all record types
dig example.com ANY

# Check specific types
dig +short A example.com
dig +short AAAA example.com
dig +short MX example.com
dig +short TXT example.com
dig +short NS example.com

# Check from external resolver
dig @8.8.8.8 example.com
dig @1.1.1.1 example.com

Use online tools: - DNSChecker.org – see propagation globally - MXToolbox.com – comprehensive DNS and email tests - IntoDNS.com – full zone health check

Step 13: Monitor DNS Propagation

DNS changes propagate gradually as TTLs expire and caches refresh.

Propagation Timeline

  • Local changes: Seconds to minutes on authoritative server
  • Global propagation: Minutes to hours depending on TTL
  • Complete propagation: Up to 24-48 hours in edge cases (stale caches)

Check Propagation

# Query multiple public resolvers
dig @8.8.8.8 example.com
dig @1.1.1.1 example.com
dig @208.67.222.222 example.com

Or use whatsmydns.net to check from dozens of global locations.

Step 14: Common DNS Record Combinations

Here's a complete zone file for a typical website with email:

$TTL 14400
@       IN  SOA     ns1.example.com. admin.example.com. (
                    2026071101 7200 3600 1209600 86400 )

; Nameservers
@       IN  NS      ns1.example.com.
@       IN  NS      ns2.example.com.

; Web hosting
@       IN  A       203.0.113.50
www     IN  CNAME   example.com.

; IPv6
@       IN  AAAA    2001:db8::1

; Mail
@       IN  MX  10  mail.example.com.
mail    IN  A       203.0.113.51

; Email authentication
@       IN  TXT     "v=spf1 mx ~all"
_dmarc  IN  TXT     "v=DMARC1; p=quarantine; rua=mailto:[email protected]"

; SSL/TLS
@       IN  CAA     0 issue "letsencrypt.org"

Conclusion

DNS configuration is methodical work that requires precision and patience. By following this checklist—setting up A, AAAA, CNAME, MX, TXT, NS, SOA, SRV, and CAA records correctly—you build a reliable foundation for your domain's web, email, and service infrastructure. Always verify changes with dig or online tools, monitor propagation, and adjust TTL values strategically around migrations. With these fundamentals in place, you can confidently manage DNS for any hosting environment.

FAQ

How long does DNS propagation take?

Typically 5 minutes to 4 hours depending on TTL values. Maximum 24-48 hours for stale caches. Lower TTL before major changes to speed propagation.

Can I use CNAME for the root domain?

No. RFC standards prohibit CNAME at the zone apex because it conflicts with required records (SOA, NS). Use A and AAAA records instead, or ALIAS/ANAME records if your DNS provider supports them.

What happens if I delete all MX records?

Email delivery to your domain will fail. Sending servers will attempt to fall back to the domain's A record, but most modern mail systems require explicit MX records.

Should I use CDN nameservers or my host's nameservers?

CDN nameservers (Cloudflare, AWS) offer better global performance, DDoS protection, and advanced features. Host nameservers are simpler for basic setups. Choose based on your traffic, security needs, and budget.

How do I test DNS changes before going live?

Use your local hosts file to override DNS:

What's the difference between TTL and DNS propagation?

TTL is how long resolvers cache a record. Propagation is the time it takes for all global resolvers to pick up your change, which depends on TTL and cache behavior.