A Record or CNAME? Choosing the Right DNS Target
Choose between an A record and a CNAME from what your provider gave you, handle the zone-apex exception, and read real dig answers column by column.
Guide library
29 guides, grouped by the layer where things usually go wrong. 29 of them include command output captured from live systems, dated so you know how fresh it is.
How record types, aliases, caches, negative answers, and signatures decide what a resolver returns for your name.
Choose between an A record and a CNAME from what your provider gave you, handle the zone-apex exception, and read real dig answers column by column.
Why DNS changes appear at different times: authoritative versus cached answers, per-cache TTL countdowns, resolver caps, and negative caching, measured live.
Why resolvers keep answering NXDOMAIN after you add a record, how your SOA sets that time, what seven DNS hosts publish, and how to launch names cleanly.
How CNAME flattening lets a zone apex follow a platform hostname, what the flattened answer hides from dig, how Cloudflare sets its TTL, and how to debug it.
What wildcard DNS records match, why wildcard certificates cover only one label, and why apps must refuse unknown hosts, tested on four platforms and our zone.
What DNSSEC changes for a website: reading the AD flag, how the registrar's DS record anchors the chain, why SERVFAIL appears, and the safe order to move DNS.
What Chrome's DNS error codes actually test, how NXDOMAIN, NODATA and SERVFAIL look in dig and curl, and which cache, resolver or record to check first.
Connecting a hostname to Cloudflare, Vercel, Netlify, and GitHub Pages, and choosing between the apex and www.
How Cloudflare's proxy status changes what dig and curl show, with dated captures from our own zone, the TTL rules, and when a record has to stay DNS only.
An ordered runbook for moving DNS to Cloudflare: export the old zone, diff old and new nameservers, settle DNSSEC, and time the overlap by real NS TTLs.
Attach a custom domain to Cloudflare Pages in the right order, then verify DNS, the per-hostname certificate, and the leftover pages.dev copy on our own site.
Vercel now assigns project-specific A and CNAME values. See what its targets resolve to today, why AAAA records cause trouble, and how to verify DNS and HTTPS.
Choose Netlify DNS or external DNS, set the apex and www records Netlify documents, and check them with dig and curl, including the IPv6 and HTTPS pitfalls.
Verify your domain, bind it in repository settings, publish GitHub's A, AAAA, or CNAME records, and confirm HTTPS, all checked against live GitHub Pages sites.
How to choose between www and the apex: DNS limits, cookies, HSTS, and SEO, redirect setups for four platforms, and a dated survey of 12 real sites.
Certificate authorization, reading a certificate from the command line, HSTS, and the TLS errors that stop a launch.
Read a site's certificate names, issuer, dates, served chain, TLS version and SNI behavior with openssl and curl, using real output and the mistakes it reveals.
What HSTS, includeSubDomains, and preload commit your subdomains to, with real headers from 100 developer sites, preload-list checks, and a ramp you can undo.
How CAs find your CAA policy, when issuewild overrides issue, and what real CAA sets and our own record-free zone show before you restrict issuance.
Map each Cloudflare 520-526 error and ERR_TOO_MANY_REDIRECTS to the hop that failed, then test the origin directly and read redirect chains with curl.
Naming, rollout, cleanup, takeover prevention, email protection, and development workflows for names that must last.
Set up a subdomain in the right order: register the host at the destination, publish the record, let the certificate issue, then verify DNS, redirects, and TLS.
Tested label and name length limits, why one IDN converts differently across libraries, where underscores belong, and how to pick subdomain labels that last.
Find every public hostname with zone exports and Certificate Transparency logs, probe DNS, HTTP, and TLS separately, and retire names in a verifiable order.
Where verification tokens go, which vendors require them to stay, what a crowded apex TXT set does to response size, and how to audit and remove old tokens.
How a leftover DNS record lets a stranger serve content on your subdomain, what unclaimed platform names look like, and the CT-based audit we ran on our zone.
The DNS records a sending domain needs for Google Workspace, Microsoft 365, or Amazon SES: SPF's 10-lookup limit, DKIM selectors, alignment, and RFC 9989 DMARC.
DNS records that stop a parked or web-only domain from being spoofed or mailed, checked against the RFCs, NCSC and CISA guidance, and live dig output.
Compare Cloudflare Quick Tunnels, ngrok's free dev domain, and an owned hostname: who picks the name, what survives restarts, and what DNS shows when it's down.
Real resolver, OS, and curl tests of .localhost and .test names on macOS, how to choose between them, and how to add HTTPS with mkcert or Caddy's internal CA.
Original measurements: how real domains are configured, and how this site itself is served.
A dated teardown of and.guide: DNS, DNSSEC, CAA, two certificates from two CAs, headers, redirects, and Markdown negotiation, plus what we would change.
Survey of 100 developer platforms' apex domains on 26 Sept 2026: CAA, DNSSEC, IPv6, HTTPS records, HSTS, apex vs www, certificate issuers, DMARC. CSV included.
Try a broader word such as DNS, HTTPS, redirect, or the name of a hosting platform.