DNS basics for a new domain
What nameservers, A, AAAA, CNAME, MX, TXT and CAA records do, how TTL and propagation work, and the SPF, DKIM and DMARC records every domain needs.
- Beginner
- 15 min read
- Updated
Tested on: Ubuntu 24.04 LTS, Debian 13, Windows 11, macOS Tahoe 26
On this page
When you register a domain, DNS decides where its website and email live. This guide explains the parts in plain language: registrar and nameservers, the records you will actually use, how changes spread, and the settings that keep your domain and email safe. Examples use the documentation addresses 203.0.113.10 and 2001:db8::10 and the domain example.com.
How DNS works in four steps
- Registry and registrar. When you register a domain, your registrar tells the registry of the extension, such as
.com, which nameservers are responsible for it. - Authoritative nameservers. These servers hold your domain's records and give the definitive answers about it.
- Recursive resolvers. Your visitors' internet providers or public resolvers look up the answer and cache it.
- Caching and TTL. Each answer is kept for as long as its time to live allows, then fetched again.
The records you will use
| Record | What it does | Example |
|---|---|---|
| A | Points a name to an IPv4 address | example.com → 203.0.113.10 |
| AAAA | Points a name to an IPv6 address | example.com → 2001:db8::10 |
| CNAME | Makes a name an alias of another name | www.example.com → example.com |
| MX | Names the mail servers, with a priority; the lowest number is tried first | 10 mail.example.com |
| TXT | Holds text such as SPF, DKIM, DMARC and verifications | v=spf1 … -all |
| NS | Lists the authoritative nameservers | set at your registrar |
| CAA | Limits which certificate authorities may issue certificates | 0 issue "letsencrypt.org" |
| SRV | Points a service to a host and port | used by some voice, chat and game services |
| PTR | Maps an IP address back to a name (reverse DNS) | set by whoever controls the IP |
Look up records yourself
Linux and macOS
dig example.com A +short
dig example.com MX +short
dig example.com TXT +short
dig NS example.com +shortWindows
Resolve-DnsName example.com -Type A
Resolve-DnsName example.com -Type MX
Resolve-DnsName example.com -Type TXT
Resolve-DnsName example.com -Type NSTo see what your own DNS host answers, without any cache, ask its nameserver directly, for example dig example.com A @ns1.example-dns.net.
The CNAME rule at the root of your domain
A name that has a CNAME record cannot have any other record. The root of your domain, example.com without www, always has NS and SOA records, so it cannot be a CNAME. Point the root to your server with A and AAAA records, and use a CNAME for www if you like. Some DNS providers offer ALIAS records or CNAME flattening, which work around this rule by answering with addresses instead.
TTL and propagation
Every record has a time to live (TTL) in seconds. A resolver that looked up your record keeps the answer that long before asking again. There is no central update that spreads across the internet: a change has "propagated" once the cached copies have expired.
- Lower the TTL in advance. A day before a planned change, lower the TTL of the records you will change, for example to 300 seconds.
- Make the change at your DNS host.
- Check what resolvers see, and query your authoritative nameserver directly to confirm the change is live.
- Raise the TTL again when the change is live everywhere.
- Allow longer for nameservers. Nameserver changes take longer, because the records at the registry have their own TTL, often one or two days.
Email records every domain needs
Email records matter even for a domain that sends no email, because they stop others from sending mail in your name.
- SPF is a TXT record that lists the servers allowed to send mail for your domain. Publish exactly one SPF record per name and keep it within the limit of ten DNS lookups.
- DKIM adds a cryptographic signature to outgoing mail. Your mail provider gives you a public key to publish as a TXT record under a selector name.
- DMARC tells receiving servers what to do with mail that fails SPF and DKIM for your domain:
p=noneto monitor,p=quarantineorp=rejectto enforce, and where to send reports. Its current specification was published as RFC 9989 in 2026.
Large mailbox providers expect this setup. Gmail, for example, requires SPF or DKIM from every sender, and SPF, DKIM and a DMARC record from senders of more than 5,000 messages a day to its users. For a domain that sends no email at all, publish an SPF record of v=spf1 -all and a DMARC policy of p=reject. Details: email deliverability.
Where to manage DNS for a HyperDC domain
- Nameservers are set in the client area: Domains › My Domains › Manage Domain › Nameservers. See manage your domain.
- Records are managed wherever your DNS is hosted: your hosting control panel when the domain uses the hosting nameservers, a DNS provider such as Cloudflare, or DNS Management on the domain page where it is enabled for your domain.
Protect the domain itself
- Registrar lock: keep the transfer lock on, so the domain cannot be moved without your approval.
- Auth code: the EPP or authorisation code moves your domain to another registrar. Keep it private.
- Automatic renewal: turn on auto renew and keep a valid payment method; expired domains can be hard and costly to recover.
- Current contact details: keep the registrant email up to date; it receives renewal and transfer notices.
- RDAP has replaced WHOIS: since January 2025, RDAP is the official source of registration data for generic domains.
- DNSSEC: signs your DNS records so resolvers can detect forged answers, where your registrar and DNS host support it.
Under ICANN's Transfer Policy, a generic domain usually cannot move to another registrar for a short period after it was registered or last transferred; country-code domains follow their own rules. A transfer of a generic domain normally adds a year to its registration.
Troubleshooting
The new record does not show up. Query the authoritative nameserver directly. If it answers correctly, wait for the old TTL; if not, the record was added at a DNS host the domain does not use.
www works but the root does not (or the other way round). Each name needs its own record. Add an A record for the root and an A record or CNAME for www.
Two SPF records. Merge them into one; with two, SPF fails for everyone.
More cases: DNS not resolving.
Next steps
- Point the domain at your server: point a domain to your server.
- Set up mail records properly: email deliverability.
Frequently asked questions
What is the difference between a registrar and a DNS host?
The registrar registers the domain and tells the registry which nameservers to use. The DNS host runs those nameservers and stores your records. Both can be the same company, but they do not have to be.
How long do DNS changes take?
As long as the TTL of the old record. Lower it before a planned change. Nameserver changes can take a day or two because of the TTLs at the registry.
Should www be a CNAME or an A record?
Either works. A CNAME pointing to the root keeps one place to update, while an A record saves a lookup. The root itself must use A and AAAA records.
Where do I manage DNS for a domain registered with HyperDC?
You change the nameservers in the client area. The records are managed wherever your DNS is hosted, for example in your hosting control panel, or with DNS Management where it is available for your domain.
What is a CAA record, and do I need one?
A CAA record lists the certificate authorities that may issue certificates for your domain. It is optional, but if you add one, include every authority you use, including the one behind free certificates, or renewals will fail.
Why does my email go to spam after I set up a new domain?
Usually because SPF, DKIM or DMARC records are missing or do not match the sending server, or the sending IP address has no reverse DNS. New domains also need time to build a sending reputation.