Skip to main content

Zone records · Editing · 5 minutes per record

How to edit DNS records — A Zone Is a List of Answers — Changing One Without Breaking the Rest

Every row in the zone is a promise your name makes to the rest of the internet, and something out there is already relying on most of them.

The short answer

A DNS record is one answer your name returns when it is asked a particular question, and editing the zone means changing what that answer is — so before you change anything, confirm the zone in front of you is the one your name actually delegates to.

Four types cover almost everything: A for an address, CNAME for an alias, MX for mail, TXT for verification and policy. The apex of a domain follows different rules from the hosts beneath it, and the TTL is the only control you have over when a change takes effect.

By the Hosting & Domains team · Reviewed 24 August 2026

Beginner

Level assumed

5

Stages per record

Free

Support, at any hour

Proven

Checked on the live panel

Every row in the zone exists because some service depends on it. Treat the list as a set of live promises rather than a settings screen, and the whole job becomes less alarming and considerably safer.

Two habits make the difference: paste values rather than typing them, and query the result from somewhere other than the machine you edited it on.

First, confirm this zone is the one being asked

A DNS panel will happily accept edits to a zone that nothing in the world consults. Look up the NS records for the domain before you start: whichever nameservers come back are the only ones resolvers ever ask. If they do not match the provider whose panel you have open, you are writing into a document nobody reads.

Names inherited from an agency or a previous supplier are where this bites. It is entirely normal to find a domain registered in one place, delegated to a second, with a third company's panel still showing a full and completely inert copy of the zone.

The record types, and what each one promises

An A record maps a name to an IPv4 address, and AAAA does the same for IPv6. A CNAME says this name is an alias of that one and follows the target wherever it moves, which is why services that shift IP addresses ask you to use one. MX names the hosts that accept mail for the domain, with a priority number in front of each. TXT carries free text, which in practice means SPF, DKIM, DMARC and verification tokens.

Two more turn up often enough to recognise. CAA lists which certificate authorities may issue for the name, and a stale one blocks issuance from everybody else. SRV publishes a service's host and port, and is normally handed to you verbatim by whichever platform needs it.

The apex is a special case

The root of the domain — yourdomain.com with nothing in front of it — cannot hold a CNAME. The standard forbids it, because the apex must also carry the NS and SOA records that define the zone, and a CNAME would override them. Panels enforce this, which is why a service asking you to CNAME the root leaves you stuck.

The answers are an A record with the address the service publishes, or an apex alias if your DNS provider offers one, which returns the target's current address while behaving like an A record. Where a service gives no fixed address at all, the usual arrangement is to serve the site from www and redirect the apex to it.

TTL is the only timing control you have

TTL tells every resolver how long it may keep an answer before asking again. It is not a delay on your edit — the authoritative zone changes the moment you save — it is how long the previous answer stays in circulation elsewhere.

The value that governs a change is the one that was in place before you made it. Lower the TTL a day ahead of any planned edit, make the change, then put it back once things have settled. Skip that and a routine record change carries a tail as long as whatever the previous TTL happened to be.

Editing without breaking the neighbours. The most common self-inflicted fault is adding a record where you meant to change one. Two A records against the same host make the name answer with one address on one query and the other on the next, which presents as an intermittent fault rather than a clear failure and can absorb a whole day before anybody suspects DNS.

Paste every value exactly as the issuing service wrote it, trailing dot included where there is one — the dot marks the name as complete, and leaving it off invites the panel to append your domain to the end of it. Keep a short text file beside the zone recording what each record is for, because 'records nobody recognises' being tidied away is how working integrations die months after anyone touched them.

Checking whether the name is still free before somebody else asks

Where these instructions were checked

Every walkthrough in this library is checked against the panel your account actually opens — cPanel's Zone Editor, the client area's domain settings, the same defaults on the same screens.

A free certificate comes with every plan and reissues itself before the old one lapses, so the padlock is never a date you have to keep in a diary.

  • Written for the person who holds the name
  • Exact record types, hosts and values
  • No step that quietly loses your mail
  • Someone reachable while the change is still landing

Why Hosting & Domains

Standard on every plan

Delegation checked before the edit

The first step is proving the zone in front of you is the one the world consults, which saves the classic wasted afternoon.

Record types with their actual promises

A, CNAME, MX and TXT, plus the CAA and SRV records you will eventually meet, each described by what it commits your name to.

The apex rule explained, not just enforced

Why the root of a domain cannot hold a CNAME, and the three legitimate ways around it.

TTL treated as a clock you can set

Lower it beforehand, change the record, put it back — the difference between minutes and most of a day.

The intermittent fault named

Two records where one was meant is the hardest DNS fault to diagnose, so it gets called out before you make it.

Verified from outside your own cache

Every change is confirmed with a query from somewhere other than the machine that made it.

Quick Start

Order placed to site online

  1. 1

    Confirm the name delegates here

    Look up the domain's NS records. If they do not name the provider whose panel is open, stop: nothing you save will ever be read. This one check prevents the majority of DNS edits that appear to do nothing.

  2. 2

    Open Zone Editor and read before you write

    In cPanel, Zone Editor lists every record the domain carries. Read the whole list first and note what each row appears to serve, particularly the TXT entries, before you change or remove anything.

  3. 3

    Lower the TTL a day ahead

    For a planned change, drop the TTL on the record concerned the day before. The old answer then falls out of circulation quickly when the edit lands, instead of lingering for whatever the previous value was.

  4. 4

    Paste the value exactly as issued

    Copy straight from the service's page — full string, correct case, trailing dot included where one is given. A stray space or a missing dot fails silently, and silent failures are what turn five minutes into an afternoon.

  5. 5

    Verify from a resolver that is not yours

    Query the record with dig or nslookup against a public resolver, or use a web lookup, before you press verify at the waiting service. Your own machine's cache is the least reliable witness available to you.

Built In

Fitted to every plan

  • Full zone control — A, CNAME, MX and TXT — from the panel
  • Free SSL on every plan, reissued before the old certificate lapses
  • Mailboxes that answer at the name you hold
  • Spam and virus screening in front of every mailbox at your name
  • PHP versions set per site from the control panel
  • cPanel, which is what most of the industry already runs
  • A daily copy, with restores you run yourself from the panel
  • People on the support desk every hour of every day
  • No set-up charge at any point, and no joining fee
  • Money back within 30 days on hosting plans, 7 on reseller

Frequently Asked

Questions we field again and again

Why can I not put a CNAME on the root of my domain?

Because the apex has to carry the NS and SOA records that define the zone, and a CNAME at the same name would override everything alongside it. The standard forbids it and panels enforce it. Use an A record with the published address, an apex alias if your provider offers one, or serve from www and redirect the root to it.

What does the trailing dot at the end of a record value mean?

It marks the name as complete rather than relative. Without it, many panels append your own domain to whatever you typed, which is how you end up with target.example.com.yourdomain.com quietly failing every lookup. Copy the value exactly as the service printed it, dot included.

How do I find out which nameservers my domain is really using?

Run a public NS lookup for the domain, or use dig NS yourdomain.com. The answer comes from the registry's delegation rather than from any provider's panel, which makes it the only authoritative statement about who is entitled to answer for the name.

Is it safe to delete a TXT record I do not recognise?

Not without checking. Verification tokens sit unread for months and then get re-checked on a schedule, so removing one un-verifies a service weeks later with nothing obvious to connect it to. Note what each record is for as you go, and leave anything unexplained where it is.

Keep reading

  • How to Choose a Domain Name

    Choosing the name whose zone you will be editing for the next decade.

  • Web Hosting

    Web hosting where the zone, the certificate and the site all answer to one account.

  • Laravel Hosting

    Laravel hosting with the records, the mail and the application administered in one panel.

Changing provider? Work through this checklist beforehand.

A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.

You get the checklist, followed now and then by a note on keeping a site responsive. Unsubscribe whenever you want; the privacy policy covers the rest.

Your name, your zone, your records.

Domains, DNS and hosting on one account, no set-up fee, and a renewal figure that does not move.

View Web Hosting plans