AAAA records and IPv6
An AAAA record maps a host name to an IPv6 address, just as an A record maps it to an IPv4 address. If a name has both, the client decides which path to take, and operating systems prefer IPv6 as soon as it is available. Many mobile networks now give devices only an IPv6 address and reach IPv4 destinations through translation at the provider (DNS64 and NAT64).
example.com. IN A 203.0.113.10
example.com. IN AAAA 2001:db8:10::10
www.example.com. IN AAAA 2001:db8:10::10Why a dead AAAA record hurts
The typical case: when moving to a new server, the A record is updated but the AAAA record keeps pointing to the old one. Or the host assigns an IPv6 address but the web server only listens on IPv4, or the firewall only lets port 443 through for IPv4.
If you have both IPv4 and IPv6, you hardly notice: Happy Eyeballs (RFC 8305) tries both paths almost simultaneously and takes whichever answers first. The site loads, everything is green at the office. In IPv6-only mobile networks, however, the device uses the AAAA record directly; translation via NAT64 only kicks in when there is none. For these visitors the site is simply unreachable. The same goes for apps, scripts and services that work without falling back to IPv4.
What the check tests
- AAAA records of the domain and of www. If you enter a subdomain such as shop.example.com, only those of that host.
- Every IPv6 address separately: clients land on any of them, one dead address among several is enough for failures.
- No answer or a server error (5xx) over IPv6: warning.
- Redirect to a target without an AAAA record: hint. The server answers over IPv6 but sends visitors to an address that is only reachable over IPv4.
- No AAAA records: hint. The website is then only reachable over IPv4, which thanks to NAT64 also works from IPv6-only networks. It costs no points in the domain check.
What "not checked" means
To fetch a website over IPv6, the checking location itself needs an IPv6 route. Without one, the check only lists the AAAA records and says clearly that reachability over IPv6 could not be verified. That is not a finding and costs no points in the domain check; it means neither that IPv6 works nor that it is broken. You can test it yourself from a machine with IPv6 using curl -6 -I https://example.com/.
Setting up IPv6 properly
Most faults do not appear at the initial setup but with later changes to the server:
- Make the web server listen on both protocols: in nginx one listen line each for IPv4 and [::], in Apache Listen 443 without a fixed IPv4 address.
- Firewall: IPv4 and IPv6 often have separate rules (iptables and ip6tables, separate entries in the host's firewall). Ports 80 and 443 must be open in both.
- Virtual hosts: a vhost bound to an IPv4 address serves the server's default site over IPv6, often with the wrong certificate.
- Moving servers: change the A and AAAA records together. If the new server has no IPv6, remove the AAAA record instead of leaving it in place.
server {
listen 443 ssl;
listen [::]:443 ssl;
server_name example.com www.example.com;
}Monitor IPv6 continuously
A dead AAAA record almost never shows up in your own checks because Happy Eyeballs masks it. When IPv6 is enabled, DomainWarn fetches the websites of all customer domains from a checking location with IPv6 over every IPv6 address, every 6 hours on the Free plan, hourly otherwise. Before every finding it verifies its own IPv6 path so that a disruption at the checking location does not trigger a false alarm.
Frequently asked questions
- Does my website have to be reachable over IPv6?
- No. Without an AAAA record, users in IPv6-only networks usually still reach the site through NAT64 at their provider. Only an AAAA record with nothing answering behind it is a problem: it is worse than none at all.
- The site loads for me, yet the check reports IPv6 as unreachable?
- Your connection probably uses IPv4, or the browser silently falls back to IPv4 via Happy Eyeballs. With curl -6 https://example.com/ you test specifically over IPv6; without IPv6 on your own connection, try it from a server.
- Why does the check test www as well?
- Visitors use both names, and both often have separate records. If www is a CNAME to a hosting provider or CDN, its AAAA record may belong to a completely different server than the one at the apex.