| Address |
|---|
| A | Maps a name to one IPv4 address. | example.com. 300 IN A 203.0.113.10 |
| AAAA | Maps a name to one IPv6 address. | example.com. 300 IN AAAA 2001:db8::10 |
| A x N | Several A records on one name hand out round-robin addresses. | 203.0.113.10 / 203.0.113.11 |
| PTR | Maps an address back to a name inside in-addr.arpa or ip6.arpa. | 10.113.0.203.in-addr.arpa. PTR host.example.com. |
| Alias & delegation |
|---|
| CNAME | Points a name at another name; the resolver chases the target until it finds addresses. | www.example.com. CNAME web-lb.example.net. |
| CNAME @ apex | A CNAME may not coexist with other records, so the zone apex cannot use one. | example.com. CNAME ext.example.net. (rejected) |
| ALIAS / ANAME | Provider-flattened apex alias that answers with A or AAAA records. | example.com ALIAS ext-hub.example.net. |
| NS | Delegates the zone, or a subzone, to its authoritative servers. | example.com. NS ns1.example.com. |
| Mail |
|---|
| MX | Lists the mail exchangers for a name. | example.com. MX 10 mail.example.com. |
| MX priority | Lower numbers win; equal numbers split the load. | 10 mail1.example.com. / 20 mail2.example.com. |
| Null MX | States that a domain accepts no mail at all (RFC 7505). | example.com. MX 0 . |
| SPF | A TXT record listing the servers allowed to send mail for the domain. | "v=spf1 include:_spf.example.com -all" |
| DKIM | Publishes the public key for one selector under _domainkey. | sel1._domainkey TXT "v=DKIM1; k=rsa; p=MIIB…" |
| DMARC | Tells receivers what to do with mail that fails SPF or DKIM. | _dmarc TXT "v=DMARC1; p=reject; rua=mailto:agg@example.com" |
| Text & verification |
|---|
| TXT | Carries arbitrary strings for protocols and humans. | example.com. TXT "v=spf1 -all" |
| TXT chunking | Each string holds at most 255 octets; long values split into quoted chunks. | ( "MIIBIjANBg" "kqhkiG9w0BAQ" ) |
| Site verification | Proves domain control to a search engine or SaaS provider. | "google-site-verification=abc123def" |
| _acme-challenge | Holds the DNS-01 token that lets a certificate authority issue. | _acme-challenge TXT "gfj9Xq3R2v" |
| Service & authority |
|---|
| SRV | Locates a service's port, priority, and weight under _service._proto. | _sip._tcp SRV 10 5 5060 sip.example.com. |
| SOA | Names the primary server, the admin mailbox, the serial, and the timers. | ns1 hostmaster 2026090401 7200 3600 1209600 300 |
| CAA | Restricts which certificate authorities may issue for the domain. | 0 issue "letsencrypt.org" |
| CAA issuewild | Governs wildcard issuance separately from host names. | 0 issuewild ";" |