Skip to content
Guide

DNS basics for a new domain

When you register a domain, DNS decides where its website and email live. This guide explains the parts in plain language: registrar and nameservers, the records you will actually use, how changes spread, and the settings that keep your domain and email safe.

At a glance

The short answer

Your registrar tells the registry which nameservers answer for your domain. Those nameservers hold the records: A and AAAA records point the domain to a server, MX records route email, and TXT records prove ownership and protect your email. Changes reach visitors as cached copies expire, which is what the TTL controls.

  • Nameservers decide who answers for your domain
  • A and AAAA records point to your server
  • MX records route your email
  • SPF, DKIM and DMARC protect your email
  • The TTL controls how fast changes spread
How it works

How DNS works in four steps

  1. Registry and registrar

    When you register a domain, your registrar tells the registry of the extension, such as .com, which nameservers are responsible for it.

  2. Authoritative nameservers

    These servers hold your domain's records and give the definitive answers about it.

  3. Recursive resolvers

    Your visitors' internet providers or public resolvers look up the answer and cache it.

  4. Caching and TTL

    Each answer is kept for as long as its time to live allows, then fetched again.

Reference

The records you will use

Examples use the documentation addresses reserved for guides like this one.

A Points a name to an IPv4 addressexample.com → 203.0.113.10
AAAA Points a name to an IPv6 addressexample.com → 2001:db8::10
CNAME Makes a name an alias of another namewww.example.com → example.com
MX Names the mail servers for the domain, with a priorityThe lowest number is tried first
TXT Holds text such as SPF, DKIM, DMARC and verificationsSeveral TXT records can exist on one name
NS Lists the authoritative nameserversSet at your registrar
CAA Limits which certificate authorities may issue SSL for the domainOptional, recommended
SRV Points a service to a host and portUsed by some voice, chat and game services
PTR Maps an IP address back to a name (reverse DNS)Set by whoever controls the IP address

The CNAME rule at the root of your domain

A name that has a CNAME record cannot have any other record. The root of your domain, example.com without www, always has NS and SOA records, so it cannot be a CNAME. Point the root to your server with A and AAAA records, and use a CNAME for www if you like. Some DNS providers offer ALIAS records or CNAME flattening, which work around this rule by answering with addresses instead.

TTL and propagation

Every record has a time to live, or TTL, in seconds. A resolver that looked up your record keeps the answer for that long before asking again. There is no central update that spreads across the internet: a change has propagated once the cached copies have expired.

  • Lower the TTL, for example to 300 seconds, a day before a planned change, and raise it again afterwards.
  • Nameserver changes take longer, because the records at the registry of your extension have their own TTL, often one or two days.
  • Check what resolvers see with dig or nslookup, and query your authoritative nameserver directly, for example with dig @ns1.example.com example.com, to confirm the change is live.

Email records every domain needs

Email records matter even for a domain that sends no email, because they stop others from sending mail in your name.

SPF

An SPF record is a TXT record that lists the servers allowed to send mail for your domain. Publish exactly one SPF record per name, and keep it within the limit of ten DNS lookups that mechanisms such as include can trigger.

DKIM

DKIM adds a cryptographic signature to outgoing mail. Your mail provider gives you a public key to publish as a TXT record under a selector name.

DMARC

DMARC tells receiving servers what to do with mail that fails the SPF and DKIM checks for your domain: p=none to monitor, p=quarantine or p=reject to enforce, and where to send reports. Its current specification was published as RFC 9989 in 2026.

Large mailbox providers expect this setup. Gmail, for example, requires SPF or DKIM from every sender, and SPF, DKIM and a DMARC record from senders of more than 5,000 messages a day to its users. For a domain that sends no email at all, publish an SPF record of v=spf1 -all and a DMARC policy of p=reject.

Domain safety

Protect the domain itself

Registrar lock

Keep the transfer lock on so the domain cannot be moved without your approval.

Auth code

The EPP or authorisation code moves your domain to another registrar. Keep it private.

Automatic renewal

Turn on auto-renewal and keep a valid payment method; expired domains can be hard and costly to recover.

Current contact details

Keep the registrant email up to date: it receives renewal and transfer notices.

RDAP has replaced WHOIS

Since January 2025, RDAP is the official source of registration data for generic domains.

DNSSEC

Signs your DNS records so resolvers can detect forged answers, where your registrar and DNS host support it.

Transfers and timing

Under ICANN's Transfer Policy, a generic domain usually cannot move to another registrar for a short period after it was registered or last transferred; country-code domains follow their own rules. Plan a transfer outside that window, and remember that a transfer of a generic domain normally adds a year to its registration.

Put your domain to work

  • Linux Web Hosting

    Our Linux Web Hosting service provides a reliable and cost-effective solution for hosting your websites. It supports a wide range of Linux-based technologies, ensuring quick and dependable performance.

    Starting from $1.59/мо
  • WordPress Web Hosting

    Our WordPress Web Hosting is optimized for WordPress-based websites, ensuring fast and secure operation. Benefit from automatic updates, backups, and specialized WordPress support.

    Starting from $2.39/мо
  • Windows Web Hosting

    Windows Web Hosting is perfect for businesses seeking to host websites and applications that rely on Windows technologies like ASP.NET and MS SQL. It offers compatibility and high performance.

    Starting from $1.59/мо
  • Linux VPS Hosting

    Linux VPS Hosting grants you more control and freedom with virtual private servers, particularly suited for Linux-based projects, offering excellent performance and customization.

    Starting from $3.33/мо

More guides

VPS vs VDS vs dedicated server

What each term means, how to tell when you have outgrown a VPS, and when bare metal is worth it.

Learn more

Choosing a macOS server for iOS CI

Xcode and macOS versions, Apple silicon, sizing, code signing and Apple's licence rules.

Learn more

Move a website without downtime

A step-by-step plan for files, databases, DNS, SSL and email.

Learn more

Secure a new Linux server

The first-hour checklist: updates, SSH keys, a firewall and backups.

Learn more

Choose a data center location

How distance becomes latency, how to measure it and what data rules mean for location.

Learn more
FAQ

Frequently asked questions

What is the difference between a registrar and a DNS host?

The registrar registers the domain and tells the registry which nameservers to use. The DNS host runs those nameservers and stores your records. Both can be the same company, but they do not have to be.

How long do DNS changes take?

As long as the TTL of the old record. Lower it before a planned change. Nameserver changes can take a day or two.

Should www be a CNAME or an A record?

Either works. A CNAME pointing to the root keeps one place to update, while an A record saves a lookup. The root itself must use A and AAAA records.

Do I need SPF, DKIM and DMARC if I only use email from my host?

Yes. Publish the records your mail provider gives you, so that your messages are delivered and others cannot easily send mail in your name.

Where do I manage DNS for a domain registered with HyperDC?

You change the nameservers of your domain in the client area. The records themselves are managed wherever your DNS is hosted, for example in your hosting control panel, or with the DNS management option where it is available for your domain.

Questions before you order?

Send us a message and our team will help you choose the right service.

Сгенерировать пароль

Please confirm