Glossary
The words you meet between a DNS dashboard and a padlock.
40 terms, each defined in a few sentences with the practical consequence that matters when something breaks. Where it helps, there is a command that shows the concept on a real name and a link to the guide that goes deeper.
A
- A record
-
Maps a name to an IPv4 address. Use it when the destination is an address you control or were told to publish; when a provider gives you a hostname instead, a CNAME usually keeps working when their addresses change.
dig example.com A +short - AAAA record
-
The IPv6 counterpart of an A record. Publishing only an A record means IPv6-only clients cannot reach the name directly; publishing a AAAA record that points at a server not listening on IPv6 breaks clients that prefer IPv6.
dig example.com AAAA +short - Apex (zone apex, root domain)
-
The top of a zone, such as example.com without any label in front. The apex must hold SOA and NS records, which is why a standard CNAME cannot live there and why hosting platforms offer flattening, ALIAS records, or fixed IP addresses for it.
C
- CAA record
-
Lists the certificate authorities allowed to issue certificates for a domain. CAs must check it before issuing; if CAA records exist and none names the CA, issuance is refused. It has no effect on certificates that already exist.
dig example.com CAA +short - Certificate Transparency (CT)
-
Public, append-only logs of issued TLS certificates. Browsers expect publicly trusted certificates to be logged, which means every hostname you put in a certificate becomes publicly searchable — useful for auditing your own names, and a reason not to put secret internal names in public certificates.
- CNAME flattening (ALIAS, ANAME)
-
A DNS provider feature that follows a CNAME-like target internally and returns the resulting A and AAAA records, allowing an alias-like setup at the apex. Resolvers only see addresses, so the configured target is invisible from outside.
- CNAME record
-
Declares that a name is an alias for another name, so the resolver continues the lookup at the target. A name with a CNAME cannot hold any other record type, and a CNAME is not a redirect: the browser keeps the original hostname, so the destination must accept it and serve a matching certificate.
dig www.example.com CNAME +short
D
- Dangling DNS record
-
A record that still points at a resource you no longer control, such as a deleted cloud bucket or an unclaimed platform site. If someone else can claim that resource, they can serve content on your name — a subdomain takeover.
- Delegation
-
The NS records in the parent zone (for example, the .com zone) that point to your DNS provider's name servers. Changing DNS providers means changing the delegation at the registrar; until it changes, the old provider keeps answering.
dig example.com NS +short - DNS-over-HTTPS (DoH)
-
DNS queries carried inside HTTPS. Public resolvers such as Cloudflare and Google expose DoH endpoints, including JSON interfaces that a web page can query directly.
- DNSSEC
-
Digital signatures on DNS data that let a validating resolver detect forged or altered answers. A validated answer carries the AD flag; a broken signature chain produces SERVFAIL on validating resolvers even though the records themselves exist.
dig example.com A +dnssec - DS record
-
Published in the parent zone through your registrar, it links the parent to your zone's DNSSEC key. A stale DS record left behind after moving DNS providers is a classic cause of a domain disappearing for validating resolvers.
dig example.com DS +short
F
- FQDN (fully qualified domain name)
-
A complete name up to the root, written in zone files with a trailing dot: www.example.com. Without the dot, many zone editors append the zone name, which is how www.example.com.example.com gets created by accident.
H
- HSTS
-
The Strict-Transport-Security response header tells browsers to use only HTTPS for a host for a set time. With includeSubDomains it covers every subdomain, and with preload a domain can be built into browsers — commitments that are slow to undo.
curl -sI https://example.com/ | grep -i strict-transport - HTTPS record (SVCB)
-
A newer DNS record type (type 65) that advertises how to connect to a service — for example supported HTTP versions and address hints — before the first connection. Older tools may show it only as TYPE65.
dig example.com TYPE65
I
- IDN and punycode
-
Internationalized domain names use Unicode characters that DNS carries in an ASCII form starting with xn--, called punycode. Look-alike characters from different scripts make IDNs a phishing concern, which is why browsers sometimes show the punycode form.
L
- Label
-
One dot-separated part of a name: www, example, and com in www.example.com. Each label can be 1 to 63 characters, and a hostname label may contain letters, digits, and hyphens, but not start or end with a hyphen.
M
- MX record
-
Names the mail servers that accept email for a domain, each with a preference number. A domain that never receives mail can publish a null MX (a single record pointing to ".") to say so explicitly.
dig example.com MX +short
N
- Negative caching
-
Resolvers also cache the answer "this name does not exist". The time comes from the zone's SOA record, so a name that someone queried before you created it can keep failing for a while after it exists.
- NODATA
-
A response with status NOERROR but no records: the name exists, just not with the type you asked for. It is different from NXDOMAIN and is often the first clue that a name is a CNAME or only has other record types.
- NS record
-
Lists the name servers that are authoritative for a zone. The NS records inside your zone should match the delegation published at the parent; a mismatch leads to inconsistent answers.
dig example.com NS +short - NXDOMAIN
-
The response code for a name that does not exist in the zone. A wildcard record prevents it for every name under the wildcard, which hides typos because every name then resolves.
P
- Propagation
-
The informal name for the time until caches everywhere pick up a DNS change. Nothing is pushed: each resolver refreshes when its cached copy's TTL runs out, which is why lowering the TTL before a change shortens the wait.
- Proxied record
-
On Cloudflare, a record with proxy enabled answers with Cloudflare's own addresses so traffic passes through its network. The origin address stays hidden from DNS, HTTP features apply at the edge, and the TTL is fixed at Auto.
- PTR record (reverse DNS)
-
Maps an IP address back to a name, under in-addr.arpa for IPv4 and ip6.arpa for IPv6. It is controlled by whoever owns the address block — usually your hosting provider — not by your domain's DNS host.
dig -x 192.0.2.10 +short
R
- Recursive resolver
-
The server that answers a device's DNS questions by asking authoritative servers and caching the results — your ISP's resolver, 1.1.1.1, or 8.8.8.8. Different resolvers can hold different cached copies of the same record at the same moment.
- Registrar
-
The company through which you register a domain. It publishes your delegation (NS) and DS records to the registry. It may also host your DNS, but registrar and DNS host are separate roles and can be different companies.
S
- SAN (Subject Alternative Name)
-
The list of hostnames a TLS certificate is valid for. Browsers check the hostname you visited against this list; the older Common Name field is no longer used for that check.
openssl s_client -connect example.com:443 -servername example.com </dev/null | openssl x509 -noout -ext subjectAltName - SNI (Server Name Indication)
-
The hostname a client sends at the start of a TLS connection so a server hosting many sites can pick the right certificate. Testing with a tool that omits SNI can show a default certificate that browsers never see.
- SOA record
-
The record at the apex that describes the zone: primary name server, contact, serial number, and timers. Its last field (the minimum) together with its own TTL sets how long negative answers are cached.
dig example.com SOA +short - SPF, DKIM, and DMARC
-
Email authentication published in DNS. SPF lists who may send mail for a domain, DKIM publishes keys that verify message signatures, and DMARC tells receivers what to do when checks fail. Domains that send no mail should still publish restrictive SPF and DMARC records.
- Subdomain
-
Any name below another name, such as docs.example.com under example.com. Creating one is just adding records in the zone, which makes subdomains cheap to create and easy to forget.
- Subdomain takeover
-
When an attacker claims the external resource a dangling record points at and serves their own content on your subdomain, often with a valid certificate. Removing the DNS record before deleting the resource prevents it.
T
- TLS certificate
-
A signed statement from a certificate authority binding hostnames to a public key, valid for a limited period. A certificate is only half the setup: the server must also present it for the right hostname and renew it before it expires.
- TTL (time to live)
-
How many seconds a resolver may cache an answer. The number you see in a resolver's answer is the time remaining on its cached copy, not the value configured in your zone. Lowering a TTL only helps for copies fetched after the change.
dig @1.1.1.1 example.com A +noall +answer - TXT record
-
Free-form text attached to a name. It carries domain-ownership verification tokens, SPF policies, DKIM keys, DMARC policies, and ACME challenge values; old verification tokens are safe to remove once the service no longer needs them.
dig example.com TXT +short
W
- Wildcard certificate
-
A certificate for *.example.com covers exactly one label: api.example.com, but not example.com itself and not v2.api.example.com. Issuance requires DNS-based validation with most ACME CAs.
- Wildcard DNS record
-
A record at *.example.com that answers for any name below it that has no records of its own. Explicitly defined names are unaffected, and a wildcard record does not bring a matching certificate or application route with it.
Z
- Zone
-
The part of the DNS namespace managed as one unit by one set of authoritative servers — for most sites, the domain and everything under it. A subdomain can also be delegated as its own zone to a different provider.