Address and alias records

A records map a name to an IPv4 address; AAAA records map it to an IPv6 address. CNAME records alias one DNS name to another. An address may belong to a content delivery network, shared hosting platform or reverse proxy rather than the website operator.

Shared addresses can help generate investigative leads, but two domains on the same IP address are not necessarily controlled by the same party. Preserve the full answer chain when a resolver returns aliases and address records together.

Delegation and mail infrastructure

NS records identify nameservers for a zone. SOA records provide zone administrative data such as serial and timer values. MX records name mail exchangers with preferences; lower preference values are favored. These records describe configuration and routing, not proof of a specific email delivery.

TXT is a general-purpose record type. It carries SPF, DMARC and domain-verification values among other uses. Do not assume every TXT record is an email security record.

Reading TTL and resolver results

TTL is a cache lifetime in seconds, not the age of the record. Different resolvers can return different answers because of caching, geographical routing, split-horizon DNS or timing. NXDOMAIN means the queried name does not exist according to the returned DNS result; a successful response without the requested record is a different condition.

  • Capture query name, type, response code, answers and TTL.
  • Separate no record from resolver failure or timeout.
  • Record the time and resolver before comparing results.
  • Do not attribute an operator solely from an IP address or nameserver.

Sources and further reading

RFC 1034 — Domain names: concepts and facilitiesRFC 1035 — Domain names: implementation and specification
This resource supports investigative triage. It is not legal advice, an attribution finding or a certification that a website is safe.