WEBINVEST.IT
Glossary

DNS record

A DNS record is an entry in a DNS zone that links a name to information needed to identify or configure an Internet service. Records are organized by name and type and served by authoritative nameservers. A domain may have multiple records simultaneously: some direct web traffic, others indicate mail servers, delegations, checks, or security policies. A record is not the domain registration and does not typically contain website files. It is part of the technical configuration that allows clients and services to discover how to reach or handle a name.

Most Common Types

The A record maps a name to an IPv4 address; AAAA performs the corresponding function for IPv6. CNAME creates an alias to another hostname, while MX specifies systems that receive mail for the domain. NS publishes the zone’s nameservers or supports subdomain delegation. TXT contains textual values used for ownership verification and email authentication. SOA describes administrative parameters of the zone and coordinates serial numbers and updates. SRV indicates hosts and ports for specific services. Each type has its own formatting rules and meaning.

MX and SRV priorities, TTLs, and other fields are part of each record’s semantics. The TTL controls how long resolvers may cache information; it does not indicate domain duration or renewal date. Records are placed with the provider hosting authoritative nameservers. Changing the zone in the registrar's panel has no effect if delegation points to different nameservers. One must verify the current authority and obtain a copy of the zone, including less obvious records.

Effects of Changes

A DNS change can affect more services than expected. Updating an A record may relocate a website, but if the same zone contains MX, SPF, or DKIM, replacing the entire configuration could disrupt email. Changing NS transfers zone responsibility and requires necessary records to already exist on the new provider. Deleting a TXT record can invalidate checks, authentication, or policies. Export or photograph the zone before changes, document reason and time, and verify impacts on web, mail, and third-party services.

Caching means that new records do not appear everywhere at once. A direct query to the authority allows checking published data; querying public resolvers helps observe caching effects. Propagation does not correct incorrect values or unready destinations. Even a syntactically valid record may point to a service that does not recognize the domain or lacks required certificates. DNS tests must be accompanied by application-level checks and log reviews.

Secure Zone Management

The DNS zone should be treated as critical configuration. Maintain an inventory of names, types, values, TTLs, purposes, and internal owners, especially for subdomains created by applications or temporary campaigns. Access to the panel must be secured, and changes authorized, because DNS compromise can redirect users to unintended servers or interrupt services. DNSSEC features add verifiability but require keys, signatures, and DS records to be coordinated: partial configuration may make the domain unreachable for validating resolvers.

During migration, compare old and new zones, apply necessary records first, and test services before changing delegations or involved values according to a documented sequence. After transition, verify authoritative and recursive responses, websites, mail, certificates, and monitoring. In short, DNS records are structured instructions describing where and how to find services associated with a name. Proper management ensures all necessary records are retained, each type’s role is respected, and every change is linked to concrete verification.

← Full glossary