---
title: "How to point a domain to a VPS: A, AAAA and CNAME records | StreetHosting"
description: "Point your domain to the VPS: A, AAAA and CNAME records, TTL and propagation, testing with dig and nslookup, and the limits of the Cloudflare proxy."
url: "https://streethosting.com.br/en/guides/vps/point-domain-to-vps"
type: "page"
language: "en-US"
---

VPS · 9 min · Beginner

Published on Jun 17, 2026 · Updated on Sep 28, 2026

# Pointing a domain to your VPS: DNS records, TTL and testing

Your site is on the VPS, but people can only reach it by IP. DNS fixes that: an A record ties the domain to the server. Learn when to use AAAA and CNAME, how TTL controls propagation, how to test with dig and what the Cloudflare proxy does not do.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Network, DNS and domains](https://streethosting.com.br/en/guides/topics/networking)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fpoint-domain-to-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fpoint-domain-to-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fpoint-domain-to-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fpoint-domain-to-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fpoint-domain-to-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=How%20to%20point%20a%20domain%20to%20a%20VPS%3A%20A%2C%20AAAA%20and%20CNAME%20records&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fpoint-domain-to-vps "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fpoint-domain-to-vps "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fpoint-domain-to-vps "Share on LinkedIn") [](https://wa.me/?text=How%20to%20point%20a%20domain%20to%20a%20VPS%3A%20A%2C%20AAAA%20and%20CNAME%20records%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fpoint-domain-to-vps "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/vps/point-domain-to-vps.md)

In this guide 8 sections

* [How DNS gets visitors to your VPS](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#o-que-e-dns)
* [A record: the main pointer](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#registro-a)
* [AAAA: only with IPv6 configured](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#aaaa)
* [CNAME, www and subdomains](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#www-e-subdominios)
* [TTL and propagation](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#propagacao)
* [Testing with dig and nslookup](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#testar)
* [The Cloudflare proxy and its limits](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#cloudflare)
* [After DNS](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#depois-do-dns)

Quick answer

To point a **domain to your VPS**, create an **A record** on the root domain with the public IPv4 of the VPS and another one for **www**, in the control panel of whoever answers for the DNS zone. Use AAAA only if the VPS has IPv6 configured. A CNAME cannot sit on the root domain. Before testing, wait for the old TTL to expire and check with `dig` on public resolvers; only then issue the HTTPS certificate.

## How DNS gets visitors to your VPS[](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#o-que-e-dns)

DNS translates an easy-to-remember name into the IP address of the machine that holds the content. Without it, people would have to memorize the IP of your VPS. There are two layers that a lot of people mix up:

* **DNS servers (NS records):** set at the domain registration, they say which provider answers for the zone. It can be Registro.br itself, Cloudflare or another DNS service.
* **Zone records:** A, AAAA, CNAME, MX and the rest. They only count at the provider the NS records point to.

The most common mistake is editing the zone in one place while the domain is delegated to another. Find out who answers for the zone before touching any record:

`dig NS seudominio.com.br +short`

If the answer shows Registro.br servers, edit the zone in the domain panel there. If it shows another provider, the records have to be created at that provider. These are the record types you will meet day to day when hosting on a VPS:

| Record | What it does                                             | Example                                     |
| ------ | -------------------------------------------------------- | ------------------------------------------- |
| A      | Ties a name to an IPv4 address                           | @ to 203.0.113.10                           |
| AAAA   | Ties a name to an IPv6 address                           | @ to 2001:db8::10, only if the VPS has IPv6 |
| CNAME  | Makes one name an alias of another name                  | www to seudominio.com.br                    |
| MX     | Names the domain's email servers                         | @ to your email provider's server           |
| TXT    | Holds text for SPF, DKIM and verifications               | @ with v=spf1 and your email rules          |
| SRV    | Gives the host and port of a service, used by some games | \_minecraft.\_tcp with the server port      |
| NS     | Says which servers answer for the zone                   | The DNS provider's servers                  |
| PTR    | Does the reverse lookup, from IP to name                 | Controlled by the owner of the IP block     |

The SRV record is what lets people join a game server without typing the port. The step by step for Minecraft is in [custom domain for a Minecraft server](https://streethosting.com.br/en/guides/minecraft/minecraft-custom-domain).

## A record: the main pointer[](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#registro-a)

1. Get the public IPv4 of the VPS from the control panel. Inside the VPS, the command `ip -4 addr show scope global` shows the same address.
2. Open the DNS zone at the provider that answers for the domain.
3. Create an A record named `@` (the root domain; some panels want the field left empty) with the VPS IP as the value.
4. Create the record for `www`, either as another A with the same IP or as a CNAME to the root domain.
5. Set the TTL. If the domain is new, 3600 seconds is fine; if it is a migration, read the propagation section first.
6. Save and delete any old A records with the same name.

Two A records on the same name, one with the old IP and one with the new, do not give you failover: resolvers return both and each visitor lands on one of them. Part of your visits go to the wrong server. When migrating, replace the value instead of creating a new record.

## AAAA: only with IPv6 configured[](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#aaaa)

AAAA is the IPv6 equivalent of A. It should only exist if the VPS really has a global IPv6 address configured and responding. Check before you create it:

`ip -6 addr show scope global # no output: the VPS has no global IPv6, do not create an AAAA # with an address listed, test from another machine with IPv6: curl -6 -I http://[2001:db8::10]`

When an AAAA exists, browsers on IPv6 networks try that address first. If it does not respond, or if Nginx and the firewall are not listening on IPv6, some visitors see slowness or errors, and certificate validation can fail. When in doubt, stick with the A record: the site works for everyone over IPv4. The guide on [IPv6 on hosting](https://streethosting.com.br/en/guides/infrastructure/how-ipv6-works) shows how to prepare the VPS once an address is available.

## CNAME, www and subdomains[](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#www-e-subdominios)

A CNAME makes one name an alias of another. It is handy for `www`: if the VPS IP changes, you only change the A record on the root domain and www follows. The rule that catches a lot of people is that **a CNAME cannot sit on the root domain**. A name with a CNAME cannot have any other record, and the root necessarily has the zone's SOA and NS records.

Some DNS providers offer a workaround, under names like CNAME flattening, ALIAS or ANAME: you write an alias at the root and the provider answers with the resolved A. For a VPS with a fixed IP you do not need any of that; an A record on the root does the job.

Subdomains follow the same logic. Create `api`, `painel` or `loja` as A records for the IP of the same VPS and let Nginx tell them apart by name, as we explain in [multiple sites on the same VPS with Nginx](https://streethosting.com.br/en/guides/vps/multiple-websites-on-one-vps). A wildcard record `*` points any subdomain to the VPS, but it also sends mistyped names to the server, so use it only if you need it.

## TTL and propagation[](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#propagacao)

There is no wave of updates sweeping across the internet. What people call propagation is the time until resolvers discard the answer they cached. What sets that time is the TTL, in seconds, of each record. With a TTL of 3600, a resolver that looked up the domain five minutes ago will not ask again for another 55 minutes.

* **New record:** usually answers within minutes. If you looked up the name before creating the record, the resolver may have cached the answer that it did not exist, and that negative answer also stays in cache for a time set by the zone.
* **Changed record:** takes up to the old TTL for everyone to see the new value.
* **Nameserver change:** the slowest, because it also depends on the delegation cache, which is usually hours and can reach a day or two.

In a migration, lower the record's TTL to 300 at least one old TTL before the switch. If it was 86400, do it a day earlier. Once the new IP is stable, go back to 3600 or more. The full playbook is in [how to migrate a server with no downtime](https://streethosting.com.br/en/guides/infrastructure/migrate-server-without-downtime).

## Testing with dig and nslookup[](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#testar)

Testing in the browser is misleading, because the browser and the operating system have their own cache. Ask the resolvers directly. On Ubuntu, `dig` comes in the `dnsutils` package:

`sudo apt install -y dnsutils dig +short seudominio.com.br A dig +short www.seudominio.com.br dig +short seudominio.com.br AAAA # different public resolvers dig @1.1.1.1 +short seudominio.com.br dig @8.8.8.8 +short seudominio.com.br # full answer, with the remaining TTL dig seudominio.com.br A # path from the root, with no cache at all dig +trace seudominio.com.br`

On Windows, use nslookup in PowerShell or the command prompt, and flush the local cache once the public answer is already right:

`nslookup seudominio.com.br 1.1.1.1 nslookup -type=AAAA seudominio.com.br 8.8.8.8 ipconfig /flushdns`

If `dig +trace` shows the right IP and your resolver does not, just wait for the TTL. If not even the trace shows it, the record was created at the wrong provider or was not saved. If the domain resolves to the right IP and the site does not open, the problem is no longer DNS: check that Nginx is listening and that the firewall allows ports 80 and 443.

## The Cloudflare proxy and its limits[](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#cloudflare)

On Cloudflare, each A, AAAA or CNAME record has two modes. With the orange cloud (proxied), the domain resolves to Cloudflare IPs, which take the connection and relay it to the VPS. With the gray cloud (DNS only), the domain resolves straight to the VPS IP. Proxied mode has limits you need to know before turning it on:

* **HTTP and HTTPS only, on fixed ports:** 80, 8080, 8880, 2052, 2082, 2086 and 2095 for HTTP; 443, 2053, 2083, 2087, 2096 and 8443 for HTTPS. Any other port does not pass through a proxied name.
* **No games, SSH or UDP:** a Minecraft server, FiveM, SSH and any UDP traffic need a record in DNS only, which exposes the real IP of the VPS. Forwarding any TCP and UDP port through Cloudflare is the job of Spectrum, available for all ports only on the Enterprise plan.
* **SSL mode:** use Full (strict) with a valid certificate on the VPS. Flexible mode talks HTTP to the origin and, combined with an HTTPS redirect in Nginx, creates an infinite loop.
* **Visitor IP:** the VPS starts seeing Cloudflare IPs. The real IP comes in the `CF-Connecting-IP` header, which Nginx has to read with the realip module so that logs and rate limiting make sense.

The proxy only hides the VPS IP if no other record in DNS only points to it. An SSH or game subdomain on the same domain gives the address away. The list of ports is in the [Cloudflare ports documentation](https://developers.cloudflare.com/fundamentals/reference/network-ports/). To publish a panel without opening any port on the VPS, see [Cloudflare Tunnel on a VPS](https://streethosting.com.br/en/guides/vps/cloudflare-tunnel-vps).

## After DNS[](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#depois-do-dns)

* NS records checked: you are editing the zone at the right provider
* A record on the root domain and on www with the correct IP
* AAAA created only if the VPS responds over IPv6
* Answer checked with dig on 1.1.1.1 and 8.8.8.8
* Email MX and TXT records recreated, if the nameservers were changed
* HTTPS certificate issued after the domain resolves

When you change the nameservers of a domain that already has email, recreate the MX and TXT records at the new provider first. Forgetting this step is the most common way to stop receiving email on migration day. If the VPS will send email, the [reverse DNS (PTR)](https://streethosting.com.br/en/guides/infrastructure/what-is-reverse-dns) matters too. It does not live in your zone: it is controlled by the owner of the IP block, and the request goes to the provider's support.

With the domain resolving, turn on HTTPS by following [SSL certificate with Let's Encrypt and Nginx](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps). If you are still choosing where to host, the [StreetHosting VPS](https://streethosting.com.br/en/vps) sits in São Paulo, activates within 60 seconds and shows the public IPv4 in the panel, ready for the A record.

In this guide

* [How DNS gets visitors to your VPS](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#o-que-e-dns)
* [A record: the main pointer](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#registro-a)
* [AAAA: only with IPv6 configured](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#aaaa)
* [CNAME, www and subdomains](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#www-e-subdominios)
* [TTL and propagation](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#propagacao)
* [Testing with dig and nslookup](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#testar)
* [The Cloudflare proxy and its limits](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#cloudflare)
* [After DNS](https://streethosting.com.br/en/guides/vps/point-domain-to-vps#depois-do-dns)

## Frequently asked questions

What is an A record?

It is the DNS record that ties a name to an IPv4 address. When someone types your domain, the resolver looks up the A record and the browser connects to your VPS IP. For a website, you normally create one A record on the root domain and another one, or a CNAME, on www.

Do I need an AAAA record too?

Only if the VPS has an IPv6 address configured and responding, which you can check with ip -6 addr show scope global. An AAAA record pointing to an address that does not respond makes visitors on IPv6 fail and can get in the way of issuing the certificate. If the VPS has no IPv6, keep just the A record.

Why doesn't the domain open yet after I set it up?

Because resolvers keep the old answer until its TTL expires. Query the domain directly against 1.1.1.1 and 8.8.8.8 with dig: if they already show the new IP, the problem is the cache on your computer or at your ISP. Changing nameservers usually takes longer than changing a record.

Can I issue the HTTPS certificate before propagation?

With HTTP validation, which is the default for Certbot with Nginx, no. The certificate authority visits the domain to check that it points to your VPS. Confirm with dig on public resolvers that the domain already answers with the right IP, and only then run Certbot.

Does the Cloudflare proxy work with a game server or SSH?

No. The proxy only relays HTTP and HTTPS on a fixed list of ports. SSH, game servers and any UDP traffic need a record in DNS only mode, which shows the real IP of the VPS. Forwarding any TCP and UDP port through Cloudflare requires Spectrum on the Enterprise plan.

Next step

See VPS plans

Root VPS in Brazil with NVMe and Anti-DDoS.

[See VPS plans](https://streethosting.com.br/en/vps)

[See Xeon VPS Xeon VPS for steady workloads, automation and long-running projects.](https://streethosting.com.br/en/vps/xeon) [See Ryzen VPS Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.](https://streethosting.com.br/en/vps/ryzen)

## Related guides

[VPS Beginner SSL certificate on a VPS with Let's Encrypt and Nginx A site without the padlock loses trust and rankings. This guide shows how to issue, renew and audit a free SSL certificate on your VPS with Nginx and Certbot. 4 min Read guide](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps) [VPS Intermediate How to set up Nginx as a reverse proxy on a VPS Your app runs on an internal port and you want to serve it on a domain with HTTPS. Nginx as a reverse proxy solves that and also brings several apps together in one place. 3 min Read guide](https://streethosting.com.br/en/guides/vps/nginx-reverse-proxy-vps) [VPS Intermediate How to host multiple websites on one VPS with Nginx A well-configured VPS can carry several small projects. The trick is separate server blocks, a default server that rejects unknown domains, one Linux user and one PHP pool per site, and independent certificates. 9 min Read guide](https://streethosting.com.br/en/guides/vps/multiple-websites-on-one-vps)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
