DNS & HTTPS: A Records, CNAME, and Common Certificate Issues

DNS is the step most likely to go wrong before a site goes live. This article explains A records vs CNAME records in the simplest terms, plus common HTTPS certificate issues.

A records vs CNAME

An A record points a domain straight to an IP address; a CNAME points a domain to another domain. A root domain (e.g. example.com) usually must use A records, while the www subdomain suits a CNAME so it updates automatically when the provider changes IPs.

Propagation time

After a change, records generally take 10 minutes to a few hours to take effect, depending on TTL. Use a public DNS checker to confirm nodes worldwide have updated.

HTTPS certificates

Most hosting platforms now issue free certificates automatically, provided DNS already points correctly to the platform. The most common failure causes: DNS not yet propagated, a conflicting old record, or a CAA record restricting the issuing authority.

Force HTTPS and redirects

Once the certificate is active, enable a 301 redirect from HTTP to HTTPS, and unify the www and non-www versions so the same content doesn't live at multiple addresses.

Checklist

Correct DNS → valid certificate → unified 301 redirects → sitemap uses the final address. Four steps and your site's access layer is stable.

More from Operations →