Definition · DNS & Email Spoofing

What is DNS Record Types?

Every entry in a DNS zone has a type, and the type determines how the data is interpreted. A resolver asks for a specific name and type together — www.example.com type A — and the authoritative name server answers with the matching records, an empty answer, or an error. Understanding the common types is the foundation for reading a zone file, diagnosing a resolution problem, or working out what an attacker can learn from your DNS.

The types you will meet most often

TypeCarriesTypical use
AAn IPv4 addressPoints a hostname at a server
AAAAAn IPv6 addressThe IPv6 equivalent of A
CNAMEAnother DNS nameAliases one name onto another
NSA name server hostnameDelegates a zone or subdomain
MXA mail host and priorityRoutes inbound email
TXTFree-form textSPF, DKIM, DMARC, ownership proofs
SOAZone administrative dataSerial number, refresh and expiry timers
PTRA DNS nameReverse DNS for an IP address
SRVHost, port and priorityService location for protocols that use it
CAAAn authorised issuerRestricts which CAs may issue certificates

Each record also carries a TTL, the number of seconds resolvers may cache it. TTLs are what produce the delay people call DNS propagation.

Why record types matter to external exposure

DNS is the map of an organisation’s internet-facing estate, so it is the first thing reconnaissance looks at. A and AAAA records reveal hosting; CNAME records reveal which third-party SaaS platforms are in use, and which of those references have gone stale; MX records reveal the mail provider; TXT records often list every vendor that has ever asked for a verification token. Where a zone transfer is left open, all of it can be pulled in a single query.

Record types also decide which security controls apply. Email authentication lives in TXT. Certificate issuance control lives in CAA. Integrity of the answers themselves depends on DNSSEC, which adds signature and key record types alongside the ones above.

See passive DNS for historical record data, subdomain enumeration for finding the names in the first place, and dangling DNS records for what happens when a record outlives the resource it points at.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.