Skip to main content

Guide library

Follow a hostname from DNS record to working HTTPS.

29 guides, grouped by the layer where things usually go wrong. 29 of them include command output captured from live systems, dated so you know how fresh it is.

DNS records & resolution

How record types, aliases, caches, negative answers, and signatures decide what a resolver returns for your name.

Updated 8 min read Tested September 26, 2026

A Record or CNAME? Choosing the Right DNS Target

Choose between an A record and a CNAME from what your provider gave you, handle the zone-apex exception, and read real dig answers column by column.

Custom domains on hosting platforms

Connecting a hostname to Cloudflare, Vercel, Netlify, and GitHub Pages, and choosing between the apex and www.

Updated 7 min read Tested September 26, 2026

Netlify Custom Domains: External DNS vs Netlify DNS

Choose Netlify DNS or external DNS, set the apex and www records Netlify documents, and check them with dig and curl, including the IPv6 and HTTPS pitfalls.

HTTPS & certificates

Certificate authorization, reading a certificate from the command line, HSTS, and the TLS errors that stop a launch.

Published 12 min read Tested September 26, 2026

Inspect a Site's TLS Certificate from the Command Line

Read a site's certificate names, issuer, dates, served chain, TLS version and SNI behavior with openssl and curl, using real output and the mistakes it reveals.

Running public hostnames

Naming, rollout, cleanup, takeover prevention, email protection, and development workflows for names that must last.

Updated 8 min read Tested September 26, 2026

How to Set Up a Subdomain: DNS, Host Routing, and HTTPS

Set up a subdomain in the right order: register the host at the destination, publish the record, let the certificate issue, then verify DNS, redirects, and TLS.

Published 14 min read Tested October 4, 2026

SPF, DKIM, and DMARC for a Domain That Sends Email

The DNS records a sending domain needs for Google Workspace, Microsoft 365, or Amazon SES: SPF's 10-lookup limit, DKIM selectors, alignment, and RFC 9989 DMARC.

Research & case studies

Original measurements: how real domains are configured, and how this site itself is served.

Updated 17 min read Tested September 26, 2026

How and.guide Is Served: A Teardown of Our Own Domain

A dated teardown of and.guide: DNS, DNSSEC, CAA, two certificates from two CAs, headers, redirects, and Markdown negotiation, plus what we would change.