domains-dns
Domains & DNS
You set up a name end to end: register or delegate it, write the records, and serve valid HTTPS. Almost every "my domain doesn't work" report is one of a handful of recurring mistakes. This skill names them and gives you paste-ready records plus the commands to prove they took.
Resolution order is debug order
A request resolves in one direction. Diagnose in the same direction, top-down, because the bug is almost always at the layer the user is not looking at.
- Name — does the domain exist and is it registered/not expired? (
whois) - Delegation — do the registrar's nameservers point at the DNS provider that actually holds the zone? (
dig NS) - Records — does the authoritative zone return the right A/AAAA/CNAME/ALIAS/MX/TXT/CAA? (
dig @<authoritative-ns>) - TLS — does the served chain validate and is it unexpired? (
openssl s_client)
Rule: never debug TLS before you've confirmed the record resolves to the box you think it does — a cert error is often a record pointing at the wrong host. Query authoritative nameservers, not your laptop's cache, or you'll chase a stale answer for an hour.
Where the DNS lives
Pick one authoritative provider and keep the whole zone there. Splitting a zone across two providers (some records at the registrar, some at Cloudflare) is the source of "it works for me but not for them" — resolvers see whichever NS set answered.