Skip to main content

Glossary

The words you meet between a DNS dashboard and a padlock.

40 terms, each defined in a few sentences with the practical consequence that matters when something breaks. Where it helps, there is a command that shows the concept on a real name and a link to the guide that goes deeper.

A

A record

Maps a name to an IPv4 address. Use it when the destination is an address you control or were told to publish; when a provider gives you a hostname instead, a CNAME usually keeps working when their addresses change.

dig example.com A +short

A records vs CNAME records

AAAA record

The IPv6 counterpart of an A record. Publishing only an A record means IPv6-only clients cannot reach the name directly; publishing a AAAA record that points at a server not listening on IPv6 breaks clients that prefer IPv6.

dig example.com AAAA +short
Apex (zone apex, root domain)

The top of a zone, such as example.com without any label in front. The apex must hold SOA and NS records, which is why a standard CNAME cannot live there and why hosting platforms offer flattening, ALIAS records, or fixed IP addresses for it.

CNAME flattening explained · www or apex?

Authoritative name server

A server that holds the zone's actual records and answers with the aa (authoritative answer) flag. It is the source of truth: if it returns the wrong value, waiting for caches to expire will not help.

dig @<name-server> www.example.com A +norec

DNS propagation, TTLs, and caches

C

CAA record

Lists the certificate authorities allowed to issue certificates for a domain. CAs must check it before issuing; if CAA records exist and none names the CA, issuance is refused. It has no effect on certificates that already exist.

dig example.com CAA +short

CAA records and Let's Encrypt · CAA record generator

Certificate Transparency (CT)

Public, append-only logs of issued TLS certificates. Browsers expect publicly trusted certificates to be logged, which means every hostname you put in a certificate becomes publicly searchable — useful for auditing your own names, and a reason not to put secret internal names in public certificates.

Subdomain inventory and cleanup

CNAME flattening (ALIAS, ANAME)

A DNS provider feature that follows a CNAME-like target internally and returns the resulting A and AAAA records, allowing an alias-like setup at the apex. Resolvers only see addresses, so the configured target is invisible from outside.

CNAME flattening explained

CNAME record

Declares that a name is an alias for another name, so the resolver continues the lookup at the target. A name with a CNAME cannot hold any other record type, and a CNAME is not a redirect: the browser keeps the original hostname, so the destination must accept it and serve a matching certificate.

dig www.example.com CNAME +short

A records vs CNAME records

D

Dangling DNS record

A record that still points at a resource you no longer control, such as a deleted cloud bucket or an unclaimed platform site. If someone else can claim that resource, they can serve content on your name — a subdomain takeover.

Dangling DNS and subdomain takeover

Delegation

The NS records in the parent zone (for example, the .com zone) that point to your DNS provider's name servers. Changing DNS providers means changing the delegation at the registrar; until it changes, the old provider keeps answering.

dig example.com NS +short
DNS-over-HTTPS (DoH)

DNS queries carried inside HTTPS. Public resolvers such as Cloudflare and Google expose DoH endpoints, including JSON interfaces that a web page can query directly.

DNS lookup and resolver comparison

DNSSEC

Digital signatures on DNS data that let a validating resolver detect forged or altered answers. A validated answer carries the AD flag; a broken signature chain produces SERVFAIL on validating resolvers even though the records themselves exist.

dig example.com A +dnssec

DNSSEC for site owners

DS record

Published in the parent zone through your registrar, it links the parent to your zone's DNSSEC key. A stale DS record left behind after moving DNS providers is a classic cause of a domain disappearing for validating resolvers.

dig example.com DS +short

F

FQDN (fully qualified domain name)

A complete name up to the root, written in zone files with a trailing dot: www.example.com. Without the dot, many zone editors append the zone name, which is how www.example.com.example.com gets created by accident.

H

HSTS

The Strict-Transport-Security response header tells browsers to use only HTTPS for a host for a set time. With includeSubDomains it covers every subdomain, and with preload a domain can be built into browsers — commitments that are slow to undo.

curl -sI https://example.com/ | grep -i strict-transport

HSTS, includeSubDomains, and preload

HTTPS record (SVCB)

A newer DNS record type (type 65) that advertises how to connect to a service — for example supported HTTP versions and address hints — before the first connection. Older tools may show it only as TYPE65.

dig example.com TYPE65

I

IDN and punycode

Internationalized domain names use Unicode characters that DNS carries in an ASCII form starting with xn--, called punycode. Look-alike characters from different scripts make IDNs a phishing concern, which is why browsers sometimes show the punycode form.

Hostname checker

L

Label

One dot-separated part of a name: www, example, and com in www.example.com. Each label can be 1 to 63 characters, and a hostname label may contain letters, digits, and hyphens, but not start or end with a hyphen.

Subdomain naming rules

M

MX record

Names the mail servers that accept email for a domain, each with a preference number. A domain that never receives mail can publish a null MX (a single record pointing to ".") to say so explicitly.

dig example.com MX +short

Lock down a domain that sends no email

N

Negative caching

Resolvers also cache the answer "this name does not exist". The time comes from the zone's SOA record, so a name that someone queried before you created it can keep failing for a while after it exists.

Why a new subdomain still says NXDOMAIN

NODATA

A response with status NOERROR but no records: the name exists, just not with the type you asked for. It is different from NXDOMAIN and is often the first clue that a name is a CNAME or only has other record types.

NS record

Lists the name servers that are authoritative for a zone. The NS records inside your zone should match the delegation published at the parent; a mismatch leads to inconsistent answers.

dig example.com NS +short
NXDOMAIN

The response code for a name that does not exist in the zone. A wildcard record prevents it for every name under the wildcard, which hides typos because every name then resolves.

Wildcard subdomains

P

Propagation

The informal name for the time until caches everywhere pick up a DNS change. Nothing is pushed: each resolver refreshes when its cached copy's TTL runs out, which is why lowering the TTL before a change shortens the wait.

DNS propagation, TTLs, and caches · TTL cutover planner

Proxied record

On Cloudflare, a record with proxy enabled answers with Cloudflare's own addresses so traffic passes through its network. The origin address stays hidden from DNS, HTTP features apply at the edge, and the TTL is fixed at Auto.

Cloudflare DNS: records and proxy status

PTR record (reverse DNS)

Maps an IP address back to a name, under in-addr.arpa for IPv4 and ip6.arpa for IPv6. It is controlled by whoever owns the address block — usually your hosting provider — not by your domain's DNS host.

dig -x 192.0.2.10 +short

R

Recursive resolver

The server that answers a device's DNS questions by asking authoritative servers and caching the results — your ISP's resolver, 1.1.1.1, or 8.8.8.8. Different resolvers can hold different cached copies of the same record at the same moment.

Compare two resolvers

Registrar

The company through which you register a domain. It publishes your delegation (NS) and DS records to the registry. It may also host your DNS, but registrar and DNS host are separate roles and can be different companies.

S

SAN (Subject Alternative Name)

The list of hostnames a TLS certificate is valid for. Browsers check the hostname you visited against this list; the older Common Name field is no longer used for that check.

openssl s_client -connect example.com:443 -servername example.com </dev/null | openssl x509 -noout -ext subjectAltName

Inspect a TLS certificate from the command line

SNI (Server Name Indication)

The hostname a client sends at the start of a TLS connection so a server hosting many sites can pick the right certificate. Testing with a tool that omits SNI can show a default certificate that browsers never see.

SOA record

The record at the apex that describes the zone: primary name server, contact, serial number, and timers. Its last field (the minimum) together with its own TTL sets how long negative answers are cached.

dig example.com SOA +short
SPF, DKIM, and DMARC

Email authentication published in DNS. SPF lists who may send mail for a domain, DKIM publishes keys that verify message signatures, and DMARC tells receivers what to do when checks fail. Domains that send no mail should still publish restrictive SPF and DMARC records.

Lock down a domain that sends no email

Subdomain

Any name below another name, such as docs.example.com under example.com. Creating one is just adding records in the zone, which makes subdomains cheap to create and easy to forget.

Subdomain setup: DNS, routing, and HTTPS

Subdomain takeover

When an attacker claims the external resource a dangling record points at and serves their own content on your subdomain, often with a valid certificate. Removing the DNS record before deleting the resource prevents it.

Dangling DNS and subdomain takeover

T

TLS certificate

A signed statement from a certificate authority binding hostnames to a public key, valid for a limited period. A certificate is only half the setup: the server must also present it for the right hostname and renew it before it expires.

Inspect a TLS certificate

TTL (time to live)

How many seconds a resolver may cache an answer. The number you see in a resolver's answer is the time remaining on its cached copy, not the value configured in your zone. Lowering a TTL only helps for copies fetched after the change.

dig @1.1.1.1 example.com A +noall +answer

TTL cutover planner

TXT record

Free-form text attached to a name. It carries domain-ownership verification tokens, SPF policies, DKIM keys, DMARC policies, and ACME challenge values; old verification tokens are safe to remove once the service no longer needs them.

dig example.com TXT +short

W

Wildcard certificate

A certificate for *.example.com covers exactly one label: api.example.com, but not example.com itself and not v2.api.example.com. Issuance requires DNS-based validation with most ACME CAs.

Check which certificates cover a name

Wildcard DNS record

A record at *.example.com that answers for any name below it that has no records of its own. Explicitly defined names are unaffected, and a wildcard record does not bring a matching certificate or application route with it.

Wildcard subdomains

Z

Zone

The part of the DNS namespace managed as one unit by one set of authoritative servers — for most sites, the domain and everything under it. A subdomain can also be delegated as its own zone to a different provider.