HTTPS and TLS certificates: what to configure and what to forget about
Certificates are free and automatic now. The remaining failures are almost all renewal automation that silently stopped working.
DNS translates domain names into addresses using record types: A and AAAA point to IP addresses, CNAME aliases one name to another, ALIAS or ANAME solves the apex-domain CNAME restriction, MX routes email, and TXT carries verification and email authentication records. TTL controls how long resolvers cache an answer, which is why you lower it before a migration.
| Record | Purpose | Example value |
|---|---|---|
| A | Name to IPv4 address | 203.0.113.10 |
| AAAA | Name to IPv6 address | 2001:db8::1 |
| CNAME | Alias to another name | cname.vercel-dns.com |
| ALIAS / ANAME | CNAME-like behaviour at the apex | Provider-specific |
| MX | Mail servers | 10 mx1.example-mail.com |
| TXT | Verification, SPF, DKIM, DMARC | v=spf1 include:… -all |
| NS | Delegates the zone | ns1.provider.com |
| CAA | Which CAs may issue certificates | 0 issue "letsencrypt.org" |
Because the DNS specification forbids a CNAME coexisting with other records at the same name, and the apex must carry NS and SOA records.
This is why example.com behaves differently from www.example.com. Providers solve it with ALIAS or ANAME records, or CNAME flattening — all of which resolve the target and serve A records at the apex. If your DNS host does not offer one of these, the workaround is a redirect from the apex to www.
TTL is how long resolvers cache a record. A TTL of 86400 means some users continue reaching the old server for a full day after you change it. Nothing you do at the registrar shortens an answer already cached elsewhere.
dig example.com A +short
dig www.example.com CNAME +short
dig example.com MX +short
dig example.com TXT +short
dig @8.8.8.8 example.com A +short # a public resolver's view
curl -I https://example.com # status, redirects, headersIt is not propagation — it is cache expiry. With a 300 second TTL set well in advance, most users see the change within minutes; stragglers with non-compliant resolvers can take a day.
A dedicated DNS provider usually offers better performance, an API, ALIAS records and DNSSEC. Separating registrar and DNS also limits the impact of a single account compromise.
It cryptographically signs DNS responses to prevent spoofing. Worth enabling for anything handling money or sensitive data; be careful, as a misconfiguration makes your domain unresolvable.
SPF lists who may send for your domain, DKIM signs messages, and DMARC tells receivers what to do when checks fail. All three are TXT records, and all three are required for reliable delivery today.
ROVQIX Engineering
Engineering team, ROVQIX
The ROVQIX engineering team builds and maintains web platforms, APIs and infrastructure for clients across SaaS, ecommerce and enterprise. These notes come out of real production work — deploys, incidents, migrations and audits.
ROVQIXdesigns and builds production web platforms — Next.js front ends, Node.js APIs and the infrastructure behind them. Tell us what you're building and we'll scope it with you.
Certificates are free and automatic now. The remaining failures are almost all renewal automation that silently stopped working.
Migrations lose traffic for one reason more than any other: a redirect map that was built quickly and never checked.
Launch day problems are almost never novel. This is the list that catches them — the same one we run on every client deployment.
No spam. Just the occasional case study and craft breakdown.