Skip to content

DNS record reference

Every record requires type, name, ttl, and a mode. TTL is 30 through 2,147,483,647 seconds. Names are lower-cased, converted to IDNA ASCII, limited to 253 characters and 63 per label, and must remain inside the managed zone. Use @ for the apex.

TypeContentAdditional rules
AIPv4 addressMay be DNS-only, Geo-DNS, or proxied
AAAAIPv6 addressLower-cased; may be DNS-only, Geo-DNS, or proxied
CNAMEDNS targetMay be DNS-only, Geo-DNS, or proxied
MXDNS targetPriority 0–65,535 required
TXT1–4,096 charactersImport joins quoted segments
NSDNS targetApex delegation changes require administrator permission
CAAflags, issue/issuewild/iodef, valueFlags 0–255
SRVDNS targetOwner begins _service._tcp, _udp, or _sctp; priority, weight, port required
PTRDNS targetOnly in managed in-addr.arpa or ip6.arpa zones

Priority, weight, and port are integers from 0 through 65,535. DNS names without a dot are relative to the zone; @ targets the apex; . is preserved as the DNS root.

Modes

ModeMeaning
dns_onlyPublish normalized content
geo_dnsPublish country, continent, then default answer sets
proxiedPublish pool routing and use origin.host as stored content

Only A, AAAA, and CNAME may be proxied. One proxied hostname has exactly one record and origin. It cannot coexist with another A, AAAA, or CNAME at the same owner. A non-apex proxied hostname becomes a CNAME and must be the only record at that owner. A proxied apex may coexist with non-routing types such as MX and TXT.

Zone-wide validation

  • Logical duplicates are rejected after normalization.
  • A published CNAME cannot coexist with another record at the same owner.
  • One Geo-DNS record must be the only record of its type at an owner.
  • Underscores are limited to valid SRV owners.
  • Record owners cannot escape the managed zone.
  • PowerDNS serials remain monotonic and are not supplied by customer records.

CDNFoundry documentation