DNS record types

You do not need every type in RFC 1035. You need the ones that take sites and mailboxes offline.

A — IPv4 address. The default “where is the website?” record. Lookup.

AAAA — IPv6 address. Harmless to omit if you are IPv4-only; harmful if it points at a dead stack. Lookup.

CNAME — alias to another name. Cannot coexist with other types on the same hostname. Not for the apex. Lookup.

MX — mail exchanger plus priority. Targets should have their own A/AAAA. Lookup.

TXT — text. SPF lives here, as do verification tokens. Lookup.

NS — authoritative nameservers for the zone. Wrong NS means you are editing a ghost. Lookup.

SOA — serial and timers. One per zone apex. Lookup.

PTR — reverse map from IP to name, under in-addr.arpa or ip6.arpa. Lookup.

CAA — which CAs may issue certificates. Lookup.

SRV — service, protocol, port, target. Query the underscored name. Lookup.

Related but not always on the apex

DMARC is TXT at _dmarc. DKIM is TXT at selector._domainkey. MTA-STS and BIMI have their own names. Treat them as records that happen to use TXT encoding, then use the specialized checkers so you do not miss the hostname.

What to query first

  1. NS — are we even talking to the right host?
  2. A/AAAA or CNAME — does the name resolve?
  3. MX + SPF + DMARC — if the ticket is about mail.
  4. CAA — if the ticket is about certificates.

Run all records when you want a snapshot, then zoom in.