🗄️ DNS Guides & Tools
Everything about how DNS actually works — record types, propagation, caching, DNSSEC, and the tools to look it all up.
🔎 Search DNS guides & tools…
Ctrl K
⭐ FEATURED
Featured Guide
Networking
DNS Propagation Guide: Why Changes Take Time & How to Speed Up
Understand TTL, resolver caching, and global propagation mechanics — plus proven techniques to minimize downtime during a DNS migration.
Read the guide →Foundations
DNS
A Record Explained: The DNS Record That Turns Names Into Addresses
A record explained from first principles — how a hostname becomes an IPv4 address, the root-to-authoritative resolution chain, caching behavior, and why almost every other DNS record exists to support this one.
DNS
AAAA Record Explained: The DNS Record Behind Every IPv6 Address
AAAA record explained from first principles — the 128-bit address it carries, why it's named the way it is, how resolution differs from an A record, and where it quietly breaks.
DNS
CNAME Explained: How DNS Aliasing Actually Works
CNAME records explained from the ground up — what a canonical name actually is, how resolvers follow the chain, why it can't sit at your apex, and where it breaks.
DNS
TXT Records: The DNS Junk Drawer That Runs Half the Internet
TXT records explained — structure, limits, how SPF/DKIM/DMARC all quietly depend on them, and why one generic text field became load-bearing infrastructure.
DNS
A Record vs CNAME: Which One Should Actually Point Where
A record vs CNAME isn't really a choice — it's a set of rules. Why the zone apex can't use a CNAME, how CNAME chaining adds resolution overhead, and a practical decision framework for every hostname you manage.
🛠️ RELATED TOOLS
DNS Tools
🗄️
DNS Lookup
Look up any DNS record type for a domain
🔁
Reverse DNS Lookup
Find the hostname behind an IP address
📧
MX Lookup
Check a domain's mail exchange records
🛡️
DNSSEC Lookup
Verify DNSSEC signing on a domain
📡
DNS Propagation Checker
See DNS propagation status worldwide
💾
DNS Cache Checker
Check what's cached at your resolver
📚 20 GUIDES
DNS Guides, Organized by Path
Configuration & Setup
DNS
How to Configure an A Record: A Practical Walkthrough
Step-by-step A record configuration across common DNS providers, apex vs subdomain setup, CDN and cloud DNS platform quirks, and how to verify a change actually took before considering it done.
DNS
How to Configure an AAAA Record: Step-by-Step for Every Major Provider
A practical, provider-by-provider walkthrough for adding an AAAA record correctly — Cloudflare, Route 53, Google Cloud DNS, Azure, and registrar panels — plus verification steps.
DNS
CDN CNAME Setup: How Content Delivery Networks Use DNS Aliasing
How CDNs use CNAME records to route traffic through their edge network, what the chain looks like in practice, and how to verify and troubleshoot a CDN CNAME setup.
DNS
Domain Verification: How Proving You Own a Domain Actually Works
How TXT-based domain verification proves ownership without credentials, the main methods services use, and where verification workflows commonly go wrong.
DNS
Google Domain Verification: TXT Method, Explained Properly
How Google's TXT-based domain verification actually works across Search Console, Workspace, and Cloud, and why it fails more often than it should.
DNS
Microsoft 365 Domain Verification: The TXT and MX Methods
How Microsoft 365 and Azure AD domain verification works, why Microsoft offers both a TXT and an MX verification path, and which one to pick.
DNS
Dual Stack DNS Explained: Running IPv4 and IPv6 Together, Correctly
What dual-stack DNS actually means, how Happy Eyeballs decides which protocol wins, and the real operational discipline dual-stack requires — firewalls, monitoring, migration.
DNS
IPv6 DNS Records: Every Record Type That Touches IPv6, Explained
A complete map of every DNS record type that interacts with IPv6 — AAAA, PTR under ip6.arpa, HTTPS/SVCB hints, glue records, and how they fit together in a real zone.
DNS
Multiple A Records: Round-Robin DNS, Load Balancing & Its Real Limits
What actually happens when a hostname has more than one A record — round-robin behavior, why DNS load balancing has no concept of server health, geo-distribution patterns, and when to use a real load balancer instead.
Advanced Topics
DNS
NSEC vs NSEC3
Proving non-existence in DNSSEC
DNS
DNSSEC Basics
A complete beginner's guide to DNS Security Extensions
DNS
DNSSEC Validation
How resolvers actually verify trust
DNS
DNSSEC Errors
A diagnostic guide to validation failures
DNS
Glue Record
Solving DNS's circular lookup problem
DNS
DNS Root Servers Explained
The 13 identities behind global name resolution
DNS
Child Name Servers
Registering in-bailiwick DNS the right way
DNS
What Is DANE?
DNS-based certificate trust, independent of the CA system
Troubleshooting & Edge Cases
DNS
A Record Errors: Decoding NXDOMAIN, SERVFAIL, and Resolution Failures
What browser and command-line errors like DNS_PROBE_FINISHED_NXDOMAIN and SERVFAIL actually mean at the A record level, which ones are real problems versus normal propagation delay, and how to fix each.
DNS
AAAA Record Troubleshooting: A Diagnostic Workflow That Actually Works
A structured way to diagnose AAAA record and IPv6 connectivity problems — from empty lookups to resolving-but-unreachable addresses to Happy-Eyeballs-masked failures.
DNS
Apex Domain Issues: Why Your Root Domain Won't Take a CNAME
Why the apex/root domain can't hold a CNAME, what breaks when people try anyway, and every practical workaround — ALIAS records, flattening, and redirect strategies.
DNS
CNAME Restrictions: Every Rule DNS Actually Enforces
A complete rulebook for CNAME restrictions — apex conflicts, coexistence rules, MX/NS interactions, provider-specific quirks, and how to work around each one correctly.
DNS
CNAME Flattening Explained: How Providers Fake an Apex CNAME
How CNAME flattening actually works under the hood, how it differs from a real CNAME and from ALIAS/ANAME records, and what to watch for across providers.
DNS
TXT Record Security: Where a Text Field Becomes an Attack Surface
The real security implications of TXT records — SPF misconfiguration, DMARC policy gaps, stale verification strings, and information disclosure risks worth auditing for.