DNS basics for a new domain
When you register a domain, DNS decides where its website and email live. This guide explains the parts in plain language: registrar and nameservers, the records you will actually use, how changes spread, and the settings that keep your domain and email safe.
The short answer
Your registrar tells the registry which nameservers answer for your domain. Those nameservers hold the records: A and AAAA records point the domain to a server, MX records route email, and TXT records prove ownership and protect your email. Changes reach visitors as cached copies expire, which is what the TTL controls.
Key takeaways
Nameservers decide who answers for your domain
A and AAAA records point to your server
MX records route your email
SPF, DKIM and DMARC protect your email
The TTL controls how fast changes spread
How DNS works in four steps
-
Registry and registrar
When you register a domain, your registrar tells the registry of the extension, such as .com, which nameservers are responsible for it.
-
Authoritative nameservers
These servers hold your domain's records and give the definitive answers about it.
-
Recursive resolvers
Your visitors' internet providers or public resolvers look up the answer and cache it.
-
Caching and TTL
Each answer is kept for as long as its time to live allows, then fetched again.
The records you will use
Examples use the documentation addresses reserved for guides like this one.
| A | Points a name to an IPv4 addressexample.com → 203.0.113.10 |
|---|---|
| AAAA | Points a name to an IPv6 addressexample.com → 2001:db8::10 |
| CNAME | Makes a name an alias of another namewww.example.com → example.com |
| MX | Names the mail servers for the domain, with a priorityThe lowest number is tried first |
| TXT | Holds text such as SPF, DKIM, DMARC and verificationsSeveral TXT records can exist on one name |
| NS | Lists the authoritative nameserversSet at your registrar |
| CAA | Limits which certificate authorities may issue SSL for the domainOptional, recommended |
| SRV | Points a service to a host and portUsed by some voice, chat and game services |
| PTR | Maps an IP address back to a name (reverse DNS)Set by whoever controls the IP address |
The CNAME rule at the root of your domain
A name that has a CNAME record cannot have any other record. The root of your domain, example.com without www, always has NS and SOA records, so it cannot be a CNAME. Point the root to your server with A and AAAA records, and use a CNAME for www if you like. Some DNS providers offer ALIAS records or CNAME flattening, which work around this rule by answering with addresses instead.
TTL and propagation
Every record has a time to live, or TTL, in seconds. A resolver that looked up your record keeps the answer for that long before asking again. There is no central update that spreads across the internet: a change has propagated once the cached copies have expired.
-
Lower the TTL in advance
A day before a planned change, lower the TTL of the records you will change, for example to 300 seconds.
-
Make the change
Update the records at your DNS host. Resolvers pick up the new values as soon as their cached copies expire.
-
Check what resolvers see
Use dig or nslookup, and query your authoritative nameserver directly, for example dig @ns1.example.com example.com, to confirm the change is live.
-
Raise the TTL again
When the change is live everywhere, set the TTL back to its usual value.
-
Allow longer for nameservers
Nameserver changes take longer, because the records at the registry of your extension have their own TTL, often one or two days.
Email records every domain needs
Email records matter even for a domain that sends no email, because they stop others from sending mail in your name.
SPF
An SPF record is a TXT record that lists the servers allowed to send mail for your domain. Publish exactly one SPF record per name, and keep it within the limit of ten DNS lookups that mechanisms such as include can trigger.
DKIM
DKIM adds a cryptographic signature to outgoing mail. Your mail provider gives you a public key to publish as a TXT record under a selector name.
DMARC
DMARC tells receiving servers what to do with mail that fails the SPF and DKIM checks for your domain: p=none to monitor, p=quarantine or p=reject to enforce, and where to send reports. Its current specification was published as RFC 9989 in 2026.
Large mailbox providers expect this setup. Gmail, for example, requires SPF or DKIM from every sender, and SPF, DKIM and a DMARC record from senders of more than 5,000 messages a day to its users. For a domain that sends no email at all, publish an SPF record of v=spf1 -all and a DMARC policy of p=reject.
Protect the domain itself
Registrar lock
Keep the transfer lock on so the domain cannot be moved without your approval.
Auth code
The EPP or authorisation code moves your domain to another registrar. Keep it private.
Automatic renewal
Turn on auto-renewal and keep a valid payment method; expired domains can be hard and costly to recover.
Current contact details
Keep the registrant email up to date: it receives renewal and transfer notices.
RDAP has replaced WHOIS
Since January 2025, RDAP is the official source of registration data for generic domains.
DNSSEC
Signs your DNS records so resolvers can detect forged answers, where your registrar and DNS host support it.
Transfers and timing
Under ICANN's Transfer Policy, a generic domain usually cannot move to another registrar for a short period after it was registered or last transferred; country-code domains follow their own rules. Plan a transfer outside that window, and remember that a transfer of a generic domain normally adds a year to its registration.
Put your domain to work
-
Linux Web Hosting
Our Linux Web Hosting service provides a reliable and cost-effective solution for hosting your websites. It supports a wide range of Linux-based technologies, ensuring quick and dependable performance.
Starting from $2.00/lu -
WordPress Web Hosting
Our WordPress Web Hosting is optimized for WordPress-based websites, ensuring fast and secure operation. Benefit from automatic updates, backups, and specialized WordPress support.
Starting from $3.00/lu -
Windows Web Hosting
Windows Web Hosting is perfect for businesses seeking to host websites and applications that rely on Windows technologies like ASP.NET and MS SQL. It offers compatibility and high performance.
Starting from $2.00/lu -
Linux VPS Hosting
Linux VPS Hosting grants you more control and freedom with virtual private servers, particularly suited for Linux-based projects, offering excellent performance and customization.
Starting from $4.20/lu
More guides
VPS vs VDS vs dedicated server
What each term means, how to tell when you have outgrown a VPS, and when bare metal is worth it.
Learn moreChoosing a macOS server for iOS CI
Xcode and macOS versions, Apple silicon, sizing, the CI runner and code signing.
Learn moreMove a website without downtime
A step-by-step plan for files, databases, DNS, SSL and email.
Learn moreSecure a new Linux server
The first-hour checklist: updates, SSH keys, a firewall and backups.
Learn moreChoose a data center location
How distance becomes latency, how to measure it and what data rules mean for location.
Learn moreFrequently asked questions
What is the difference between a registrar and a DNS host?
The registrar registers the domain and tells the registry which nameservers to use. The DNS host runs those nameservers and stores your records. Both can be the same company, but they do not have to be.
How long do DNS changes take?
As long as the TTL of the old record. Lower it before a planned change. Nameserver changes can take a day or two.
Should www be a CNAME or an A record?
Either works. A CNAME pointing to the root keeps one place to update, while an A record saves a lookup. The root itself must use A and AAAA records.
Do I need SPF, DKIM and DMARC if I only use email from my host?
Yes. Publish the records your mail provider gives you, so that your messages are delivered and others cannot easily send mail in your name.
Where do I manage DNS for a domain registered with HyperDC?
You change the nameservers of your domain in the client area. The records themselves are managed wherever your DNS is hosted, for example in your hosting control panel, or with the DNS management option where it is available for your domain.
What is a CAA record, and do I need one?
A CAA record lists the certificate authorities that may issue SSL certificates for your domain. It is optional, but it stops other authorities from issuing certificates in your name. If you add one, include every authority that issues certificates for you, including the one your host uses for free certificates, or renewals will fail.
Can I point my domain to HyperDC without transferring it?
Yes. The domain can stay with its current registrar: change its A and AAAA records, or its nameservers, to the values of your HyperDC service. A transfer is only needed if you also want to manage the registration and renewals here, and you can do that later, at any time outside the transfer lock period.
Why does my email go to spam after I set up a new domain?
Usually because SPF, DKIM or DMARC records are missing or do not match the server that sends your mail. Publish the records your mail provider gives you, keep exactly one SPF record per name, and make sure the sending server's IP address has a reverse DNS (PTR) name. New domains also need some time to build a sending reputation.
Questions before you order?
Send us a message and our team will help you choose the right service.