---
title: "DNS records"
description: "Reference for DNS record types in Edge DNS: A, AAAA, CNAME, ALIAS, MX, TXT, CAA and SRV, with examples and best practices for TTLs and email authentication."
url: "https://edge.network/docs/dns/records"
section: "DNS"
---

# DNS records

DNS records map domain names to IP addresses, mail servers and other destinations. Learn about each record type and when to use it.

![Records tab of a DNS zone in Control](/media/docs/control-dns-records.svg)

## A record (IPv4 address)

Maps a domain name to an IPv4 address. This is the most common record type, used to point your domain to a web server.

Example:

| Name | TTL | Data |
|---|---|---|
| `@` | `300` | `185.199.108.153` |

> [!NOTE]
> Use `@` for the root domain (`example.com`) or a subdomain name like `www` or `api`.

## AAAA record (IPv6 address)

Maps a domain name to an IPv6 address. Use it alongside A records for dual-stack connectivity.

Example:

| Name | TTL | Data |
|---|---|---|
| `@` | `300` | `2606:4700:3033::ac43:b4a7` |

## CNAME record (canonical name)

Creates an alias from one domain to another. The browser follows the CNAME to find the actual IP address.

Example:

| Name | TTL | Data |
|---|---|---|
| `www` | `300` | `example.com` |

> [!WARNING]
> **CNAME restrictions.** CNAME records cannot be created at the zone apex (`@`). Use an **ALIAS** record instead for root domain aliasing.

## ALIAS record

An Edge-specific record that works like a CNAME but can be used at the zone apex. Perfect for pointing your root domain to a load balancer, CDN or another hostname.

Example:

| Name | TTL | Data |
|---|---|---|
| `@` | `300` | `cdn.edge.network` |

ALIAS records are resolved at query time: Edge DNS looks up the target hostname and returns the IP addresses directly to the client.

## MX record (mail exchange)

Specifies the mail servers responsible for receiving email for your domain. MX records include a priority value. Lower numbers have higher priority.

Example (Google Workspace):

| Priority | Name | Data |
|---|---|---|
| 1 | `@` | `aspmx.l.google.com` |
| 5 | `@` | `alt1.aspmx.l.google.com` |
| 5 | `@` | `alt2.aspmx.l.google.com` |

## TXT record (text)

Stores arbitrary text data. Commonly used for domain verification, SPF, DKIM and DMARC.

- **SPF record (email authentication):** `v=spf1 include:_spf.google.com ~all`
- **Domain verification:** `google-site-verification=abc123...`
- **DMARC policy:** `v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com`

## CAA record (Certification Authority Authorization)

Specifies which certificate authorities (CAs) are allowed to issue SSL certificates for your domain. Helps prevent unauthorised certificate issuance.

Example:

```text
@ CAA 0 issue "letsencrypt.org"
@ CAA 0 issuewild "letsencrypt.org"
@ CAA 0 iodef "mailto:security@example.com"
```

> [!NOTE]
> **CAA tags:**
>
> - `issue`: CAs allowed to issue certificates
> - `issuewild`: CAs allowed to issue wildcard certificates
> - `iodef`: email or URL to report violations to

## SRV record (service)

Specifies the location of services like SIP, XMPP or LDAP. Includes priority, weight, port and target hostname.

Format:

```text
_service._protocol.name TTL SRV priority weight port target
```

Example (SIP):

```text
_sip._tcp.example.com 300 SRV 10 60 5060 sip.example.com
```

## Best practices

- **Use appropriate TTLs:** use lower TTLs (60–300s) for frequently changing records and higher TTLs (3600–86400s) for stable records to reduce DNS lookups.
- **Always add both A and AAAA:** if your server supports IPv6, add both record types for the best connectivity.
- **Configure email authentication:** set up SPF, DKIM and DMARC TXT records to prevent email spoofing.
- **Add CAA records:** restrict which CAs can issue certificates to improve security.

## Next steps

- [Geographic routing](/docs/dns/geo-routing) — Route traffic by visitor location
- [Zone management](/docs/dns/zones) — Create and configure zones
