Technical

A record

A record is the DNS record that maps a hostname to one or more IPv4 addresses. It is the last lookup a resolver does before the browser opens a TCP connection.

How it is measured

Query it directly: `dig +short example.com A` prints the addresses, and plain `dig example.com A` also shows the TTL in seconds. A name can carry several A records and resolvers may reorder them, so compare the whole set, not the first line.

Ask the authoritative server (`dig @ns1.yourdns.net example.com A`) and then a public resolver such as 1.1.1.1. If the two answers differ, you are looking at a cache or a half-finished change, not at two truths.

Worked example

A bakery on a WordPress host moves from a shared server at 203.0.113.40 to a VPS at 198.51.100.7. The owner edits the A record for `www.crumbtown.example` at 10:00. Her laptop still loads the old site because the old record had a 14,400-second TTL and her ISP resolver cached it at 10:05.

At 14:05 that cache expires and `dig` starts returning 198.51.100.7. A phone on mobile data, using a different resolver, saw the new server at 11:20. Same record, two clocks.

How it differs

An A record answers with an IPv4 address. An AAAA record answers with an IPv6 address. A host with only an A record is invisible to an IPv6-only client, and a host with only an AAAA record is invisible to an IPv4-only one. Neither record can point at another name; that job belongs to a CNAME.

Common errors

Typing a hostname into the A field instead of an address. Leaving a stale second A record from the old host, so half of requests reach a dead server. Forgetting that `www` and the bare domain are separate records. Editing zone data at the registrar while the live nameservers sit at another provider. Lowering the TTL after the change instead of a day before it.

In practice

Before a migration, drop the TTL to 300 seconds a day ahead. Change the record, then check it with `dig` against the authoritative server and two public resolvers. Delete the old value rather than keeping it as a fallback, because round-robin DNS is not a health check.

See also

AAAA record, CNAME

Sources

Count this on a real site.

Watch my website