DNS Lookup: How It Works
DNS translates names into addresses. When a website is unreachable, an email bounces, or a change 'has not taken effect yet', DNS is the first place to look — and a lookup tool answers most of those questions in seconds.
The record types
| Type | Points to | Used for |
|---|---|---|
| A | An IPv4 address | The main website record |
| AAAA | An IPv6 address | IPv6 connectivity |
| CNAME | Another hostname | Aliases — www to the root, CDN endpoints |
| MX | A mail server, with priority | Email delivery |
| TXT | Arbitrary text | SPF, DKIM, DMARC, domain verification |
| NS | Authoritative nameservers | Delegation |
| SOA | Zone metadata | Serial number, refresh timings |
| PTR | A hostname, from an address | Reverse lookup, mail server reputation |
Propagation is really caching
'DNS propagation' is a misleading phrase. Nothing spreads outward — a change is live at your authoritative nameserver immediately. What takes time is resolvers around the world expiring their cached copy of the old answer.
That expiry is governed by the record's TTL, in seconds. A 24-hour TTL means some resolvers serve the old value for up to a day. The practical technique: lower the TTL to 300 seconds at least 24 hours before a planned change, make the change, confirm it, then raise the TTL again. Doing this after the change has no effect, because the long TTL is already cached.
The email records
- SPF — a TXT record listing which servers may send mail for the domain. Only one SPF record is permitted; two is a common misconfiguration that causes both to fail.
- DKIM — a public key used to verify a cryptographic signature on each message.
- DMARC — a policy telling receivers what to do when SPF and DKIM fail, and where to send reports.
All three are now effectively required for reliable delivery to major providers. Mail from a domain without them is increasingly filtered or rejected outright, and a missing or broken record here is the usual cause of 'our emails go to spam'.
The CNAME restriction
A CNAME cannot coexist with any other record for the same name. This means the root of a domain — example.com with no subdomain — cannot use a CNAME, because it must carry SOA and NS records. Providers work around this with ALIAS or ANAME records that behave like a CNAME while returning an A record. This is why 'point your root domain at our CDN' is often more complicated than pointing www at it.
A diagnostic order
- Check the authoritative nameservers with an NS lookup — if those are wrong, nothing else matters.
- Query the authoritative server directly to see the intended answer.
- Query a public resolver to see what the world currently sees.
- Compare. A difference means caching, and the TTL tells you how long it will last.
Also check the registrar: a domain that has expired or has its nameservers unset will resolve to nothing regardless of how the zone is configured.