No. Zone generation is plain JavaScript in your browser. Your domain, IP addresses, nameservers and records never leave your machine — important, because a zone file describes your entire infrastructure.
Generate a complete, valid BIND zone file from a form — 17 record types from A to the modern HTTPS/SVCB records, auto-incrementing YYYYMMDDnn serial, bulk paste-and-validate, DNSSEC signing steps and primary / secondary transfer config. Everything is built in your browser.
A missing dot, a serial nobody incremented, a CNAME colliding with an A record — these stay silent until mail stops flowing or the site resolves from one ISP and not from another. This builder generates the zone file from a form, validates addresses, priorities and quoting as you go, and hands you the exact DNSSEC signing and transfer commands to deploy it.
Every byte is produced by JavaScript in your browser. Your domain, IP plan and records are never uploaded — a zone file is a complete map of your infrastructure, and it stays on your machine.
Origin, admin email, TTL and nameservers — the SOA record and serial are built for you.
17 types: A, AAAA, CNAME, MX, TXT, NS, SRV, CAA, PTR, NAPTR, SSHFP, TLSA, HTTPS, SVCB, ZONEMD, DS and DNAME.
IP format, MX priority, TXT quoting, CNAME conflicts and glue records are checked before output.
Copy the zone, run the DNSSEC steps, drop in the primary/secondary config and test with dig.
| Name | Type | Value |
|---|
Tip: build the full SPF, DKIM and DMARC records with our SPF / DKIM / DMARC generator, then paste the values here as TXT rows.
Generates the primary and secondary zone blocks for named.conf, the TSIG key commands, and the dig commands to verify the AXFR and the serial propagation.
The zone above carries the TXT records, but the values decide whether your mail is delivered or silently dropped. Build all three records correctly — including selectors, keys and aggregate reports — with our free SPF / DKIM / DMARC generator, then paste them into this zone builder.
Everything above runs in JavaScript in your browser. Your domain, IP addresses and DNS records are never uploaded — a zone file is a complete map of your infrastructure, and it stays on your machine.
| Type | Purpose | Example value |
|---|---|---|
| A | Name to IPv4 address | 192.0.2.10 |
| AAAA | Name to IPv6 address | 2001:db8::10 |
| CNAME | Alias to another name (no other record may share the name) | www.example.com. |
| MX | Mail exchanger with priority | 10 mail.example.com. |
| TXT | Text: SPF, DKIM, DMARC, verification tokens | "v=spf1 a mx ~all" |
| NS | Delegation to a nameserver | ns1.example.com. |
| SRV | Service location (SIP, XMPP, autodiscover) | 10 60 5060 sip.example.com. |
| CAA | Which Certificate Authorities may issue for the zone | 0 issue "letsencrypt.org" |
| PTR | Reverse lookup (address to name) | host.example.com. |
| NAPTR | Rule-based rewrite for SIP / ENUM | 100 10 "S" "SIP+D2U" "!^.*$!sip:info@example.com!" . |
| SSHFP | Fingerprint of the SSH host key (RFC 6594) | 2 1 |
| TLSA | DANE: TLS certificate association on port 443 | 3 1 1 |
| HTTPS | Modern aliasing + connection hints (RFC 9460) | . alpn=h2,h3 or svc.example.com. |
| SVCB | General service binding (RFC 9460) | 1 svc.example.com. alpn=h2 |
| ZONEMD | Cryptographic digest of the whole zone (RFC 8976) | 1 1 |
| DS | Delegation signer — the DNSSEC trust anchor for a child zone | 2371 13 2 |
| DNAME | Redirect a whole subtree of names (RFC 6672) | old.example.com. |
| SOA | Start of authority — built automatically from the form | serial refresh retry expire negTTL |
For the mail-critical TXT values — SPF, DKIM and DMARC — use the dedicated SPF / DKIM / DMARC generator so senders, selectors and report addresses are exactly right.
No. Zone generation is plain JavaScript in your browser. Your domain, IP addresses, nameservers and records never leave your machine — important, because a zone file describes your entire infrastructure.
The date tells you when the zone last changed, and the two-digit counter lets you edit it up to 99 times per day. The builder auto-increments: same day means the counter goes up, a new day resets it to 01. Secondaries only pull a transfer when the serial grows — a wrong serial is the classic reason an edit never propagates.
They come from RFC 9460 and replace the older ALPN-specific hacks. HTTPS lets a name point at another server (for CDNs and quic-friendly setups) and carry connection hints such as alpn=h2,h3 or port=8443 in one record. SVCB is the general form for non-HTTP services. Both are supported in this builder and in current BIND, Unbound, PowerDNS and Knot versions.
Each is just a TXT record, but the values are where people fail. Build them with the SPF / DKIM / DMARC generator: it produces the exact SPF policy, the DKIM record with your selector and public key, and a DMARC policy with reporting addresses. Paste the three results into this builder as TXT rows and the zone is mail-complete.
DNSSEC signatures cannot be produced by a browser form alone — they need your private keys. The builder emits the exact command sequence: dnssec-keygen to create the Zone Signing Key and Key Signing Key, dnssec-signzone (or BIND inline-signing) to produce the RRSIG and NSEC records, the DS record to publish at your registrar, and delv or dig to verify the chain. The transfer config already includes inline-signing yes for BIND.
Zone transfers (AXFR and the incremental IXFR) should never be world-readable. The generated config allows transfers only from the listed secondary IPs, sends notify messages to them automatically, and — with the TSIG option — requires a shared HMAC key on both ends, so nobody can spoof a secondary and pull your whole zone. The dig commands confirm the transfer works and the serial propagated.
Two commands cover it: named-checkzone example.com /etc/named/zones/db.example.com catches syntax errors before reload, and named-checkconf validates the named.conf blocks. After reload, query with dig @localhost example.com SOA and confirm the serial, then test from an external resolver. The bulk tab also reports duplicates, bad addresses and CNAME conflicts before the zone ever reaches the server.
CAA tells Certificate Authorities which of them may issue certificates for your domain — with it, only Let Us Encrypt (or your chosen CA) can issue; every other CA must refuse. It is free protection against mis-issuance, all major CAs check it, and the builder includes a default row you can edit.