DNS Record Types
A reference for every DNS record type you are likely to meet, from A and CNAME through SRV, CAA and DNSSEC records to the newer HTTPS and SVCB service bindings, each with its numeric type and a realistic example.
| Type | Numeric | Purpose | Example |
|---|---|---|---|
| A | 1 | Maps a hostname to an IPv4 address. | example.com. 300 IN A 93.184.216.34 |
| AAAA | 28 | Maps a hostname to an IPv6 address. | example.com. 300 IN AAAA 2606:2800:220:1:248:1893:25c8:1946 |
| CNAME | 5 | Alias pointing one name at another. Cannot coexist with other records at the same name. | www.example.com. 300 IN CNAME example.com. |
| MX | 15 | Mail exchanger for the domain, with a preference value (lower wins). | example.com. 300 IN MX 10 mail.example.com. |
| NS | 2 | Delegates a zone to a set of authoritative nameservers. | example.com. 86400 IN NS ns1.example.com. |
| TXT | 16 | Arbitrary text. Carries SPF, DKIM, DMARC and domain-ownership proofs. | example.com. 300 IN TXT "v=spf1 -all" |
| SOA | 6 | Start of authority: the primary nameserver, admin contact, serial and timers for a zone. | example.com. 3600 IN SOA ns1.example.com. admin.example.com. 1 7200 3600 1209600 3600 |
| PTR | 12 | Reverse DNS: maps an IP back to a hostname. Mail servers check this. | 34.216.184.93.in-addr.arpa. IN PTR example.com. |
| SRV | 33 | Locates the host and port for a named service. | _sip._tcp.example.com. IN SRV 10 60 5060 sip.example.com. |
| CAA | 257 | Restricts which certificate authorities may issue certificates for the domain. | example.com. IN CAA 0 issue "letsencrypt.org" |
| DS | 43 | Delegation signer: the DNSSEC link from a parent zone to a child. | example.com. IN DS 12345 13 2 49FD... |
| DNSKEY | 48 | Public key used to verify DNSSEC signatures in a zone. | example.com. IN DNSKEY 256 3 13 mdsswUy... |
| RRSIG | 46 | The DNSSEC signature covering a record set. | example.com. IN RRSIG A 13 2 300 ... |
| NSEC / NSEC3 | 47 / 50 | Proves that a name or record type does not exist, without revealing the whole zone. | example.com. IN NSEC3 1 0 0 - ... |
| HTTPS | 65 | Service binding for HTTPS: advertises ALPN, port and IP hints so clients can connect faster. | example.com. IN HTTPS 1 . alpn="h3,h2" |
| SVCB | 64 | Generic service binding record; HTTPS is the web-specific form. | _svc.example.com. IN SVCB 1 svc.example.net. |
| TLSA | 52 | Pins a certificate or public key to a name for DANE validation. | _443._tcp.example.com. IN TLSA 3 1 1 0B9F... |
| SSHFP | 44 | Publishes SSH host key fingerprints so clients can verify them via DNS. | example.com. IN SSHFP 4 2 9DBA... |
| NAPTR | 35 | Naming authority pointer, used for ENUM and SIP service discovery. | example.com. IN NAPTR 100 10 "U" "E2U+sip" "!^.*$!sip:info@example.com!" . |
| DNAME | 39 | Redirects an entire subtree of names, like a CNAME for everything beneath a name. | old.example.com. IN DNAME new.example.com. |
| CDS / CDNSKEY | 59 / 60 | Child-published DS/DNSKEY used to automate DNSSEC key rollover with the parent. | example.com. IN CDS 12345 13 2 49FD... |
| LOC | 29 | Geographic location of the host. | example.com. IN LOC 51 30 12.0 N 0 7 39.0 W 0m |
| HINFO | 13 | Host CPU and operating system. Rarely used; some servers return it to refuse ANY queries. | example.com. IN HINFO "RFC8482" "" |
| URI | 256 | Maps a name to a URI for a given service. | _ftp._tcp.example.com. IN URI 10 1 "ftp://ftp.example.com/" |
| OPENPGPKEY | 61 | Publishes an OpenPGP public key for an email address. | hash._openpgpkey.example.com. IN OPENPGPKEY ... |
| SPF | 99 | Deprecated dedicated SPF type. Publish SPF in a TXT record instead. | Obsolete — use TXT |
| ANY | 255 | Requests all record types. Most providers now refuse it (RFC 8482) to limit amplification. | Usually answered with HINFO |
About this reference
A reference for every DNS record type you are likely to meet, from A and CNAME through SRV, CAA and DNSSEC records to the newer HTTPS and SVCB service bindings, each with its numeric type and a realistic example.
This page is static data served straight from the edge, so it loads instantly and works without JavaScript. Filtering happens in your browser — nothing you type is sent anywhere.