Setting up DNS records correctly is foundational to hosting websites, routing email, and running services. This guide walks you through every major DNS record type with numbered steps, example configurations, and practical commands you can run today.
Prerequisites: What You Need Before You Start
Before configuring DNS records, ensure you have:
- Domain name ownership – registered with any registrar
- Access to DNS management – via your registrar, hosting control panel (cPanel, Plesk), or dedicated DNS provider (Cloudflare, Route 53)
- Target IP addresses or hostnames – know where your records should point
- SSH or control panel access – if you're managing your own nameserver
Step 1: Understand Your DNS Zone Structure
Every domain has a DNS zone containing all its records. The zone is managed by authoritative nameservers (listed in NS records).
Check Your Current Nameservers
Run this command to see which nameservers currently host your domain's zone:
dig +short NS example.com
Or:
nslookup -type=NS example.com
The output shows your authoritative nameservers. All DNS changes must be made on those servers.
Step 2: Set Up A Records (IPv4 Addresses)
An A record maps a hostname to an IPv4 address. This is the most common record type.
When to Use A Records
- Point your domain root (
example.com) to a web server - Map subdomains (
www.example.com,blog.example.com) to specific IPs - Direct traffic to any IPv4-based service
Configuration Steps
Via cPanel DNS Zone Editor:
- Log into cPanel
- Navigate to Zone Editor under Domains
- Click Manage next to your domain
- Click + A Record
- Enter:
- Name:
@(for root domain) or subdomain likewww- TTL:14400(4 hours) or3600(1 hour) - Address: Your server's IPv4 (e.g.,203.0.113.50) - Click Add Record
Via BIND Zone File:
@ IN A 203.0.113.50
www IN A 203.0.113.50
blog IN A 203.0.113.75
Verify:
dig +short A example.com
You should see your configured IPv4 address.
Step 3: Set Up AAAA Records (IPv6 Addresses)
An AAAA record ("quad-A") maps a hostname to an IPv6 address.
When to Use AAAA Records
- Your server has IPv6 connectivity
- You want to serve traffic over IPv6
- Modern best practice for dual-stack hosting
Configuration Steps
Via cPanel:
- Zone Editor → Manage → + AAAA Record
- Enter:
- Name:
@or subdomain - IPv6 Address:2001:db8::1(your actual IPv6) - TTL:14400 - Add Record
Via Zone File:
@ IN AAAA 2001:db8::1
www IN AAAA 2001:db8::1
Verify:
dig +short AAAA example.com
Step 4: Set Up CNAME Records (Aliases)
A CNAME record creates an alias that points one hostname to another.
When to Use CNAME Records
- Point
www.example.comtoexample.com - Route subdomains to external services (CDN, email platform)
- Never use CNAME at the domain root (technical restriction)
Configuration Steps
Via cPanel:
- Zone Editor → + CNAME Record
- Enter:
- Name:
wwwor subdomain - CNAME:example.com.(note the trailing dot) - TTL:14400 - Add Record
Via Zone File:
www IN CNAME example.com.
shop IN CNAME shops.shopify.com.
Verify:
dig +short CNAME www.example.com
Common Pitfall
CNAME records cannot coexist with other record types for the same hostname. If www has a CNAME, it cannot also have an A, MX, or TXT record.
Step 5: Set Up MX Records (Mail Routing)
An MX record directs email to your mail servers. Priority values determine routing order (lower number = higher priority).
When to Use MX Records
- Configure email delivery for your domain
- Route mail through Google Workspace, Microsoft 365, or your own mail server
Configuration Steps
Via cPanel:
- Zone Editor → + MX Record
- Enter:
- Priority:
10(primary server),20(backup) - Destination:mail.example.com.or external mail server - TTL:14400 - Add Record
Example for Google Workspace:
@ IN MX 1 aspmx.l.google.com.
@ IN MX 5 alt1.aspmx.l.google.com.
@ IN MX 5 alt2.aspmx.l.google.com.
@ IN MX 10 alt3.aspmx.l.google.com.
@ IN MX 10 alt4.aspmx.l.google.com.
For Your Own Mail Server:
@ IN MX 10 mail.example.com.
@ IN MX 20 mail2.example.com.
Ensure the mail server hostnames have corresponding A or AAAA records.
Verify:
dig +short MX example.com
Step 6: Set Up TXT Records (Verification & Policy)
A TXT record holds arbitrary text data. Common uses include SPF, DKIM, DMARC, and domain verification.
When to Use TXT Records
- SPF: authorize sending mail servers
- DKIM: cryptographic email authentication
- DMARC: email policy and reporting
- Domain verification (Google, Microsoft, SSL providers)
Configuration Steps
SPF Record Example:
@ IN TXT "v=spf1 mx include:_spf.google.com ~all"
DKIM Record Example:
default._domainkey IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCS..."
DMARC Record Example:
_dmarc IN TXT "v=DMARC1; p=quarantine; rua=mailto:[email protected]"
Domain Verification Example:
@ IN TXT "google-site-verification=abc123xyz"
Via cPanel:
- Zone Editor → + TXT Record
- Enter:
- Name:
@,_dmarc, or specific subdomain - TXT Data: Your policy string in quotes - TTL:14400 - Add Record
Verify:
dig +short TXT example.com
dig +short TXT _dmarc.example.com
Step 7: Set Up NS Records (Nameserver Delegation)
An NS record delegates a zone or subdomain to specific nameservers.
When to Use NS Records
- Delegate a subdomain to another DNS provider
- Point your domain to external nameservers (Cloudflare, AWS Route 53)
Configuration Steps
NS records for the domain root are typically managed at your registrar, not in the zone itself.
Subdomain Delegation Example:
shop IN NS ns1.shopify.com.
shop IN NS ns2.shopify.com.
This delegates all DNS queries for shop.example.com to Shopify's nameservers.
At Registrar (for root domain):
- Log into your domain registrar
- Find Nameserver or DNS settings
- Enter your chosen nameservers:
-
ns1.example.com-ns2.example.com- Or external:ns1.cloudflare.com,ns2.cloudflare.com - Save changes
Verify:
dig +short NS example.com
Step 8: Set Up SOA Record (Zone Authority)
The SOA (Start of Authority) record defines the authoritative nameserver and zone parameters.
When to Use SOA Records
You typically don't manually create SOA records—your DNS server generates them automatically. However, understanding them is essential for troubleshooting.
SOA Record Structure
example.com. IN SOA ns1.example.com. admin.example.com. (
2026071101 ; Serial (YYYYMMDDnn)
7200 ; Refresh
3600 ; Retry
1209600 ; Expire
86400 ; Minimum TTL
)
Parameters Explained:
- Serial: Increment this when you change the zone (triggers secondary server updates)
- Refresh: How often secondary servers check for updates
- Retry: Wait time if refresh fails
- Expire: When secondary servers discard data if primary is unreachable
- Minimum TTL: Default TTL for negative responses
Verify:
dig SOA example.com
Step 9: Set Up SRV Records (Service Discovery)
An SRV record specifies the location of services (host and port).
When to Use SRV Records
- Configure Microsoft services (SIP, Office 365)
- XMPP/Jabber chat servers
- LDAP directory services
- Game servers and VoIP
Configuration Steps
Format:
_service._protocol.name TTL IN SRV priority weight port target
Example for SIP:
_sip._tcp IN SRV 10 60 5060 sipserver.example.com.
Example for Minecraft:
_minecraft._tcp IN SRV 0 5 25565 mc.example.com.
Via cPanel:
- Zone Editor → + SRV Record
- Enter:
- Service:
_sip- Protocol:_tcp- Priority:10- Weight:60- Port:5060- Target:sipserver.example.com. - Add Record
Verify:
dig +short SRV _sip._tcp.example.com
Step 10: Set Up CAA Records (Certificate Authority Authorization)
A CAA record restricts which certificate authorities can issue SSL/TLS certificates for your domain.
When to Use CAA Records
- Prevent unauthorized SSL certificate issuance
- Required by some compliance frameworks
- Increase domain security posture
Configuration Steps
Allow Let's Encrypt:
example.com. IN CAA 0 issue "letsencrypt.org"
Allow DigiCert and report violations:
example.com. IN CAA 0 issue "digicert.com"
example.com. IN CAA 0 iodef "mailto:[email protected]"
Forbid all issuance:
example.com. IN CAA 0 issue ";"
Via cPanel:
- Zone Editor → + CAA Record
- Enter:
- Tag:
issue- Value:letsencrypt.org - Add Record
Verify:
dig +short CAA example.com
Step 11: Set TTL Values Strategically
TTL (Time To Live) determines how long resolvers cache your DNS records.
Recommended TTL Values
- Before migration: Lower to
300(5 minutes) for quick rollback - After migration: Raise to
3600(1 hour) or14400(4 hours) - Stable records: Use
86400(24 hours) - MX and NS records: Keep at
14400or higher
How to Update TTL
Most DNS interfaces let you specify TTL per record. Lower values increase query load but allow faster changes. Higher values reduce DNS traffic and improve performance.
Step 12: Verify All Records
After configuration, verify every record:
# Check all record types
dig example.com ANY
# Check specific types
dig +short A example.com
dig +short AAAA example.com
dig +short MX example.com
dig +short TXT example.com
dig +short NS example.com
# Check from external resolver
dig @8.8.8.8 example.com
dig @1.1.1.1 example.com
Use online tools: - DNSChecker.org – see propagation globally - MXToolbox.com – comprehensive DNS and email tests - IntoDNS.com – full zone health check
Step 13: Monitor DNS Propagation
DNS changes propagate gradually as TTLs expire and caches refresh.
Propagation Timeline
- Local changes: Seconds to minutes on authoritative server
- Global propagation: Minutes to hours depending on TTL
- Complete propagation: Up to 24-48 hours in edge cases (stale caches)
Check Propagation
# Query multiple public resolvers
dig @8.8.8.8 example.com
dig @1.1.1.1 example.com
dig @208.67.222.222 example.com
Or use whatsmydns.net to check from dozens of global locations.
Step 14: Common DNS Record Combinations
Here's a complete zone file for a typical website with email:
$TTL 14400
@ IN SOA ns1.example.com. admin.example.com. (
2026071101 7200 3600 1209600 86400 )
; Nameservers
@ IN NS ns1.example.com.
@ IN NS ns2.example.com.
; Web hosting
@ IN A 203.0.113.50
www IN CNAME example.com.
; IPv6
@ IN AAAA 2001:db8::1
; Mail
@ IN MX 10 mail.example.com.
mail IN A 203.0.113.51
; Email authentication
@ IN TXT "v=spf1 mx ~all"
_dmarc IN TXT "v=DMARC1; p=quarantine; rua=mailto:[email protected]"
; SSL/TLS
@ IN CAA 0 issue "letsencrypt.org"
Conclusion
DNS configuration is methodical work that requires precision and patience. By following this checklist—setting up A, AAAA, CNAME, MX, TXT, NS, SOA, SRV, and CAA records correctly—you build a reliable foundation for your domain's web, email, and service infrastructure. Always verify changes with dig or online tools, monitor propagation, and adjust TTL values strategically around migrations. With these fundamentals in place, you can confidently manage DNS for any hosting environment.
