DNS maps names to things. That is the whole idea, and almost every problem you will hit comes from forgetting that the mapping is cached, distributed and eventually consistent rather than instantaneous.

Records are just typed answers to a question. The type tells the resolver what kind of answer to expect.

The records you will actually use

  • A — maps a name to an IPv4 address.
  • AAAA — maps a name to an IPv6 address.
  • CNAME — points one name at another name. The resolver then looks that name up. Only valid where an A/AAAA record is allowed, which is why you cannot put one on the apex of a domain.
  • MX — says where mail for the domain should be delivered, with a priority number.
  • TXT — free-form text, and the record everyone abuses. SPF, DKIM, DMARC and most domain-verification schemes live here.
  • NS — delegates a zone to a set of name servers.
  • SRV — service location: host and port for a named service.

TTL is the reason your change has not worked yet

Every record carries a time to live in seconds. Resolvers are allowed to cache the answer for that long. If you change a record with a 24 hour TTL, some proportion of the internet will keep using the old value for up to 24 hours.

Lower the TTL well before a planned change — at least one old-TTL period in advance — and raise it again afterwards. Doing this the other way round is the single most common migration mistake.

Debugging order

  • Query the authoritative name server directly to confirm what is actually published.
  • Query a public resolver to see what the rest of the world sees.
  • Check the local resolver cache and the OS resolver cache.
  • Only then start suspecting the application.