Free Server Tool — 100% In-Browser

DNS Zone Builder

Generate a complete, valid BIND zone file from a form — 17 record types from A to the modern HTTPS/SVCB records, auto-incrementing YYYYMMDDnn serial, bulk paste-and-validate, DNSSEC signing steps and primary / secondary transfer config. Everything is built in your browser.

example.com. @ A 192.0.2.10 www CNAME @ @ MX 10 mail @ HTTPS . alpn=h2 TLSA / SSHFP serial 2026101001 DNSSEC signed ZONEMD + DS

A Zone File Is the One Config Typo You Notice Last

A missing dot, a serial nobody incremented, a CNAME colliding with an A record — these stay silent until mail stops flowing or the site resolves from one ISP and not from another. This builder generates the zone file from a form, validates addresses, priorities and quoting as you go, and hands you the exact DNSSEC signing and transfer commands to deploy it.

Every byte is produced by JavaScript in your browser. Your domain, IP plan and records are never uploaded — a zone file is a complete map of your infrastructure, and it stays on your machine.

How It Works

1. Zone Basics

Origin, admin email, TTL and nameservers — the SOA record and serial are built for you.

2. Add Records

17 types: A, AAAA, CNAME, MX, TXT, NS, SRV, CAA, PTR, NAPTR, SSHFP, TLSA, HTTPS, SVCB, ZONEMD, DS and DNAME.

3. Validate & Generate

IP format, MX priority, TXT quoting, CNAME conflicts and glue records are checked before output.

4. Deploy & Sign

Copy the zone, run the DNSSEC steps, drop in the primary/secondary config and test with dig.

DNS Zone Builder

Zone basics

Serial number

Records

NameTypeValue

Tip: build the full SPF, DKIM and DMARC records with our SPF / DKIM / DMARC generator, then paste the values here as TXT rows.

Paste records

Servers

Generates the primary and secondary zone blocks for named.conf, the TSIG key commands, and the dig commands to verify the AXFR and the serial propagation.

Mail records: SPF, DKIM and DMARC

The zone above carries the TXT records, but the values decide whether your mail is delivered or silently dropped. Build all three records correctly — including selectors, keys and aggregate reports — with our free SPF / DKIM / DMARC generator, then paste them into this zone builder.

Everything above runs in JavaScript in your browser. Your domain, IP addresses and DNS records are never uploaded — a zone file is a complete map of your infrastructure, and it stays on your machine.

Record Type Reference

TypePurposeExample value
AName to IPv4 address192.0.2.10
AAAAName to IPv6 address2001:db8::10
CNAMEAlias to another name (no other record may share the name)www.example.com.
MXMail exchanger with priority10 mail.example.com.
TXTText: SPF, DKIM, DMARC, verification tokens"v=spf1 a mx ~all"
NSDelegation to a nameserverns1.example.com.
SRVService location (SIP, XMPP, autodiscover)10 60 5060 sip.example.com.
CAAWhich Certificate Authorities may issue for the zone0 issue "letsencrypt.org"
PTRReverse lookup (address to name)host.example.com.
NAPTRRule-based rewrite for SIP / ENUM100 10 "S" "SIP+D2U" "!^.*$!sip:info@example.com!" .
SSHFPFingerprint of the SSH host key (RFC 6594)2 1
TLSADANE: TLS certificate association on port 4433 1 1
HTTPSModern aliasing + connection hints (RFC 9460). alpn=h2,h3 or svc.example.com.
SVCBGeneral service binding (RFC 9460)1 svc.example.com. alpn=h2
ZONEMDCryptographic digest of the whole zone (RFC 8976)1 1
DSDelegation signer — the DNSSEC trust anchor for a child zone2371 13 2
DNAMERedirect a whole subtree of names (RFC 6672)old.example.com.
SOAStart of authority — built automatically from the formserial refresh retry expire negTTL

For the mail-critical TXT values — SPF, DKIM and DMARC — use the dedicated SPF / DKIM / DMARC generator so senders, selectors and report addresses are exactly right.

DNS Zone Builder — FAQ

Is my domain or IP plan uploaded anywhere?

No. Zone generation is plain JavaScript in your browser. Your domain, IP addresses, nameservers and records never leave your machine — important, because a zone file describes your entire infrastructure.

Why YYYYMMDDnn for the serial?

The date tells you when the zone last changed, and the two-digit counter lets you edit it up to 99 times per day. The builder auto-increments: same day means the counter goes up, a new day resets it to 01. Secondaries only pull a transfer when the serial grows — a wrong serial is the classic reason an edit never propagates.

What are the HTTPS and SVCB records?

They come from RFC 9460 and replace the older ALPN-specific hacks. HTTPS lets a name point at another server (for CDNs and quic-friendly setups) and carry connection hints such as alpn=h2,h3 or port=8443 in one record. SVCB is the general form for non-HTTP services. Both are supported in this builder and in current BIND, Unbound, PowerDNS and Knot versions.

How do I add SPF, DKIM and DMARC to this zone?

Each is just a TXT record, but the values are where people fail. Build them with the SPF / DKIM / DMARC generator: it produces the exact SPF policy, the DKIM record with your selector and public key, and a DMARC policy with reporting addresses. Paste the three results into this builder as TXT rows and the zone is mail-complete.

How does the DNSSEC block work?

DNSSEC signatures cannot be produced by a browser form alone — they need your private keys. The builder emits the exact command sequence: dnssec-keygen to create the Zone Signing Key and Key Signing Key, dnssec-signzone (or BIND inline-signing) to produce the RRSIG and NSEC records, the DS record to publish at your registrar, and delv or dig to verify the chain. The transfer config already includes inline-signing yes for BIND.

Primary and secondary — how do transfers stay secure?

Zone transfers (AXFR and the incremental IXFR) should never be world-readable. The generated config allows transfers only from the listed secondary IPs, sends notify messages to them automatically, and — with the TSIG option — requires a shared HMAC key on both ends, so nobody can spoof a secondary and pull your whole zone. The dig commands confirm the transfer works and the serial propagated.

How do I check the zone before loading it?

Two commands cover it: named-checkzone example.com /etc/named/zones/db.example.com catches syntax errors before reload, and named-checkconf validates the named.conf blocks. After reload, query with dig @localhost example.com SOA and confirm the serial, then test from an external resolver. The bulk tab also reports duplicates, bad addresses and CNAME conflicts before the zone ever reaches the server.

What is a CAA record and do I need one?

CAA tells Certificate Authorities which of them may issue certificates for your domain — with it, only Let Us Encrypt (or your chosen CA) can issue; every other CA must refuse. It is free protection against mis-issuance, all major CAs check it, and the builder includes a default row you can edit.

Related Free Server Tools

24/7 Support Available:

Our support team is here to assist you around the clock. Get Expert Help, Anytime.