DNS (Domain Name System) translates domain names like mystore.com into the IP addresses computers use to find each other. DNS also decides where your email is delivered, and whether your order confirmations land in the customer’s inbox or in spam. Most people only think about DNS when something goes wrong, typically when switching hosting. Here we explain how it works, which records you need to know, and what to watch out for as a store owner.
How a DNS lookup works
When someone types your address into a browser, the computer first asks a resolver, usually at the internet provider or a public service, for the address. If the resolver has the answer fresh in memory, it replies right away. Otherwise it starts at the top: one of the internet’s root servers points to the servers for the extension, such as .com, which in turn point to the name servers responsible for your particular domain. They reply with the record that was asked for, usually the IP address of your web server. The resolver sends the answer back and remembers it for a while, so the next visitor gets it faster. The whole round trip usually takes a few milliseconds.
Name servers: who controls your DNS?
The name servers hold the official answers for your domain, and which name servers a domain uses is registered with the registrar (for .dk domains, that’s Punktum dk, the Danish registry). Many people simply leave DNS with the registrar or the hosting provider; others move it to a separate DNS service, for example at a CDN, so hosting and email can sit with different providers without being tied to each other.
There’s no single right answer. What matters is that you know where your DNS lives, that you have access yourself, and that the login is protected with two-factor authentication. Whoever can change your DNS can point both your website and your email somewhere else.
The DNS records you need to know
| Record | What it does | Example use |
|---|---|---|
| A | Points a name to an IPv4 address | mystore.com → the web server |
| AAAA | Points a name to an IPv6 address | Same as A, for IPv6 |
| CNAME | Points a name to another name | www.mystore.com → mystore.com |
| MX | Says where email for the domain is delivered | Your email provider |
| TXT | Free text, used for verification and email security | SPF, DKIM, DMARC, Search Console verification |
| NS | Lists the domain’s name servers | ns1.provider.com |
| CAA | Says who may issue certificates for the domain | Only Let’s Encrypt |
DNS and email: getting order emails delivered
For an online store, email is the part of DNS that most often causes problems without anyone noticing. Order confirmations, invoices and password resets are sent from your domain, and the big email providers reject or spam-filter mail from domains that can’t prove they’re allowed to send it. The customer simply never sees the order confirmation and writes to you, or buys somewhere else next time.
The proof consists of three TXT records that work together. SPF is a list of the servers allowed to send mail from your domain, and if the store sends mail itself, or through a mail service, it has to be on the list. DKIM signs each email digitally, so the recipient can see it hasn’t been changed on the way and really comes from you. DMARC ties the two together by telling recipients what to do with mail that fails the checks, and it can send you reports, so you can see who is sending in your name.
The typical mistake is that WordPress sends mail directly from the web server, which is neither in SPF nor signing with DKIM. Instead, set WordPress up to send through a transactional email service or your email provider’s SMTP, and make sure all three records are in place.
TTL, and changes that take time
Every record has a TTL (time to live) that says how long resolvers may remember the answer. If it’s set to a day, some visitors can be sent to the old server for up to a day after a change. So lower the TTL, to five minutes for example, a couple of days before a planned move.
DNS when you switch hosting
- Find out who controls your DNS today, and take a copy of all records, not just the A record.
- Lower the TTL a couple of days in advance.
- Move the site, and test it on the new server, for example through your local hosts file.
- Update the A and AAAA records, or switch name servers if the new provider is going to handle DNS. Recreate the MX and TXT records, so email keeps working.
- Check that SSL and HTTPS work on the new server, and that the certificate can renew.
- Keep the old server running until traffic has moved, and watch for orders that may have landed on it.
Read more about choosing a provider in our guide to WordPress hosting.
DNS and security
The biggest risk is rarely technical. It’s a weak login at the registrar or DNS provider, or a domain that expires because the renewal notice went to an old email address. Protect both with two-factor authentication, and keep an eye on renewals. On top of that, DNSSEC can sign your DNS answers so they can’t be forged on the way, and CAA records can limit who may issue certificates for your domain. Most registries and providers support both.
Frequently asked questions
How long does a DNS change take?
It depends on the TTL of the old record. With a low TTL, the change has reached most people within minutes; with a high one, it can take a day or more.
Why do my order emails end up in spam?
Usually because SPF, DKIM or DMARC is missing or set up wrong, or because mail is sent directly from the web server. Check your TXT records, and send through a mail service that signs for your domain.
Moving hosts, or is DNS acting up?
We move online stores without downtime and set up DNS and email correctly as part of our hosting and infrastructure service.