Technical

AAAA record

AAAA record is the DNS record that maps a hostname to an IPv6 address. Clients that support IPv6 usually try it first and fall back to the A record if the connection fails.

How it is measured

`dig +short example.com AAAA` returns 128-bit addresses written as hex groups, such as 2001:db8:44::12. An empty answer with status NOERROR means the name exists but has no IPv6 address, which is normal and not a fault.

Test the path as well as the record: `curl -6 -I https://example.com` forces IPv6 and shows whether anything listens there. A record that resolves to an address with no server bound to it is worse than no record at all.

Worked example

An Astro docs site on a VPS gets an AAAA record for `docs.fernlab.example` pointing at 2001:db8:44::12. `dig` resolves it from the laptop, but `curl -6` hangs for 30 seconds. nginx has `listen 80;` and no `listen [::]:80;` line.

One line in the server block and a reload later, `curl -6` returns 200 in 90 ms. The access log then starts showing IPv6 client addresses from mobile carriers, roughly a third of requests that week.

How it differs

An AAAA record carries an IPv6 address; an A record carries an IPv4 one. A dual-stack host publishes both under the same name. The name comes from the width: 128 bits is four times the 32 of IPv4, hence four A's.

Common errors

Publishing an AAAA that points at a retired CDN range. Adding the record before the firewall allows port 443 over IPv6. Assuming IPv4 monitoring proves IPv6 works. Pasting an address with a typo that still parses. Deleting the A record because everyone is supposedly on IPv6 now.

In practice

If you publish an AAAA, probe it separately: one uptime check over IPv6 and one over IPv4. If you cannot test the v6 path, remove the record until you can. Check that your log format stores a client address wide enough for IPv6 strings.

See also

A record, DNS

Sources

Count this on a real site.

Watch my website