NSEC : Next-Secure record (RFC 4034)
Part of DNSSEC—used to prove a name does not exist. Uses the same format as the (obsolete) NXT record.
SIG : Signature (RFC 2535)
Signature record used in SIG(0) (RFC 2931). Until RFC 3755 was published, the SIG record was part of DNSSEC; now RRSIG is used for that.
DS : Delegation signer (RFC 4034)
The record used to identify the DNSSEC signing key of a delegated zone
SRV : Service locator (RFC 2782)
Generalized service location record, used for newer protocols instead of creating protocol-specific records such as MX.
Key record that can be used with IPSEC
OPT : Option (RFC 2671)
This is a 'pseudo DNS record type' needed to support EDNS
DHCID : DHCP identifier (RFC 4701)
Used in conjunction with the FQDN option to DHCP
IXFR : Incremental Zone Transfer (RFC 1995)
Requests a zone transfer of the given zone but only differences from a previous serial number. This request may be ignored and a full (AXFR) sent in response if the authoritative server is unable to fulfill the request due to configuration or lack of required deltas.
SSHFP : SSH Public Key Fingerprint (RFC 4255)
Resource record for publishing SSH public host key fingerprints in the DNS System, in order to aid in verifying the authenticity of the host.
DLV : DNSSEC Lookaside Validation record (RFC 4431)
For publishing DNSSEC trust anchors outside of the DNS delegation chain. Uses the same format as the DS record. RFC 5074 describes a way of using these records.
KEY : Key record (RFC 4034)
Used only for TKEY (RFC 2930). Before RFC 3755 was published, this was also used for DNSSEC, but DNSSEC now uses DNSKEY.
DNAME : delegation name (RFC 2672)
DNAME will delegate an entire portion of the DNS tree under a new name. In contrast, the CNAME record creates an alias of a single name. Like the CNAME record, the DNS lookup will continue by retrying the lookup with the new name.
SOA : start of authority record (RFC 1035)
Specifies authoritative information about a DNS zone, including the primary name server, the email of the domain administrator, the domain serial number, and several timers relating to refreshing the zone.
TSIG : Transaction Signature (RFC 2845)
Record that supports one set of security mechanisms for DNS. Used to secure communication between DNS resolvers and Name servers, in contrast to DNSSEC, which secures the actual DNS records from the authoritative name server.
NSEC3 : NSEC record version 3 (RFC 5155)
An extension to DNSSEC that allows proof of nonexistence for a name without permitting zonewalking
AFSDB : AFS database record (RFC 1183)
Location of database servers of an AFS cell. This record is commonly used by AFS clients to contact AFS cells outside their local domain. A subtype of this record is used by the obsolete DCE/DFS file system.
PTR : pointer record (RFC 1035)
Pointer to a canonical name. Unlike a CNAME, DNS processing does NOT proceed, just the name is returned. The most common use is for implementing reverse DNS lookups, but other uses include such things as DNS-SD.
TKEY : Transaction Key (RFC 2930)
One way of providing a key to be used with TSIG
