All articles
Guides

How to point a domain to a VPS: A record, www and DNS check

In short

To point a domain at a VPS, create an A record named @ with the server's IP address in the domain's DNS settings, and for www either a CNAME to the main domain or a second identical A record. A new record usually shows up within minutes, a changed one after the old TTL expires; check the result with dig +short your-domain.

Key takeaways
  • A domain is pointed at a VPS with an A record: name @ (the domain root), value - the server's IPv4 address; for www add a CNAME to the main domain or a second A record with the same IP.
  • A new DNS record usually becomes visible within minutes, while a change to an existing one shows up only after its previous TTL (cache time in seconds, often 3600 = 1 hour) expires.
  • To check where a domain points, run dig +short example.com on Linux and macOS or nslookup example.com on Windows - the answer must be your server's IP.
  • In Cloudflare, the grey cloud (DNS only) gives visitors the server's real IP, while the orange cloud (Proxied) hides it behind Cloudflare and passes only HTTP and HTTPS.

Step 1. Find the server's IPv4 address

You need the VPS's public IPv4 address. At Tihost it is shown in the panel under «My Servers» and in the Telegram bot @tihost_bot. If you later change the server IP (Tihost lets you do it once for free), update the A records too - otherwise the domain keeps pointing at the old address.

Step 2. Create an A record for the domain

Open DNS management at your registrar or wherever the domain's NS servers are delegated (Cloudflare, for example). Delete old A records for the domain root - usually the registrar's parking page - and add your own:

TypeName (host)ValueTTL
A@203.0.113.103600 or Auto
Awww203.0.113.103600 or Auto
CNAMEwwwexample.com3600 or Auto
For www pick one of the last two rows: a second A record or a CNAME.

@ means the domain itself without a subdomain; some panels want the field left empty or the full domain typed in. Leave NS and MX records alone: the first delegate the domain, the second handle email.

Step 3. CNAME or a second A record for www?

A CNAME is handier for www: it refers to the main domain, so changing the IP means editing a single A record. A second A record works just as fast, but you will have to change the IP in two places. The DNS standard does not allow a CNAME on the domain root itself - the root always gets an A record.

For the site to open both with and without www, both names need a record, and the HTTPS certificate is then issued for both at once - as shown in the nginx and Let's Encrypt guide.

Do you need an AAAA record?

An AAAA record is the same as an A record but for an IPv6 address. Create one only if the server really has an IPv6 address and the site answers on it. A wrong AAAA record is worse than none: some visitors and the Let's Encrypt certificate authority will go over IPv6 and fail even though IPv4 works.

Step 4. How long does a DNS update take?

  • A new record for a name that did not exist before is usually visible within minutes.
  • A changed record updates everywhere only after its previous TTL expires: up to an hour with a TTL of 3600, up to a day with 86400.
  • Changing NS servers (moving DNS to Cloudflare, for example) can take up to 24-48 hours - that is how long the top-level domain zone records are cached.
  • Before moving to a new server, lower the TTL to 300 seconds a day in advance - the switch then takes minutes.

Step 5. Check that the domain points at the server

On Linux and macOS use dig (the dnsutils package on Ubuntu and Debian). The first two commands ask your current DNS resolver, the others ask Cloudflare's and Google's public resolvers: once they return the new IP, the record has updated.

bash
dig +short example.com A
dig +short www.example.com
dig @1.1.1.1 +short example.com A
dig @8.8.8.8 +short example.com A

On Windows, nslookup does the same in PowerShell or Command Prompt; the second argument is the DNS server to ask:

Windows
nslookup example.com
nslookup www.example.com 1.1.1.1

If public resolvers already see the new IP but your browser does not, it is the local cache: on Windows ipconfig /flushdns clears it, otherwise just wait for the TTL to run out.

Cloudflare: orange cloud or grey cloud?

If Cloudflare hosts the domain's DNS, every A record has a toggle. The grey cloud (DNS only) is a plain record pointing straight at the server. The orange cloud (Proxied) routes traffic through Cloudflare's network, which changes several things at once:

Grey cloud (DNS only)Orange cloud (Proxied)
What dig returnsYour server's IPCloudflare IP addresses
Certificate the visitor seesYours, from the server (e.g. Let's Encrypt)Cloudflare's; between Cloudflare and the server it depends on the SSL mode
Which ports workAny: website, SSH, games, databasesOnly HTTP and HTTPS on a limited set of ports; SSH and game servers will not connect via that name
Visitor IP in server logsThe real oneA Cloudflare IP; the real one is in the CF-Connecting-IP header
Caching and traffic filteringNoYes, on Cloudflare's side

What next: a website and HTTPS

The domain points at the server - now install a web server and a free certificate: nginx and Let's Encrypt step by step. If you run an app on the server, see how to run Node.js on a VPS. And if the server is not set up yet, start with the first VPS setup.

Launch a server in 2 minutes

AMD Ryzen 9, NVMe and DDoS protection in Germany, Finland and Poland. Pay with crypto or card.

Order a Server

FAQ

Which DNS record makes a domain point to a VPS?

You need an A record: name @ (the domain root), value - the server's public IPv4 address. For www add a CNAME to the main domain or a second A record with the same IP.

How long does DNS take to update after changing an A record?

A new record usually appears within minutes, a changed one after the previous TTL expires, most often within an hour. Changing the domain's NS servers can take up to 24-48 hours.

Can I put a CNAME on the domain root?

The DNS standard does not allow it: the domain root already has SOA and NS records, and a CNAME cannot coexist with other records. Use an A record for the root and CNAMEs for subdomains like www.

How do I check which IP a domain points to?

On Linux and macOS run dig +short example.com, on Windows nslookup example.com. The answer must be your VPS IP address; to bypass the local cache, ask a public resolver: dig @1.1.1.1 +short example.com.

What is the difference between Cloudflare's orange and grey cloud?

The grey cloud (DNS only) points the domain straight at the server and passes any port. The orange cloud (Proxied) routes traffic through Cloudflare: the server IP is hidden, only HTTP and HTTPS work, and visitors see Cloudflare's certificate.

Do I need to change DNS if my VPS IP address changes?

Yes: A records point at a specific IP, so after the server address changes they must be updated to the new one. Until the old TTL expires, some visitors will still reach the previous address.