InfraNestInfraNest
DNS

DNS Zone

A DNS zone is an administratively autonomous portion of the DNS namespace, defined by delegation, for which a specific set of nameservers is authoritative and which contains a SOA record at its apex.

A DNS zone is a distinct part of the DNS namespace assigned to a specific group of authoritative nameservers. Every zone must contain exactly one SOA record at its apex (the zone's top-level name), which identifies the primary server, administrator contact, and versioning information.

Zones differ from domains: a domain like example.com can contain multiple zones if subdomains are delegated to separate nameservers. Delegation happens via NS records in the parent zone pointing to child nameservers. If those child nameservers are inside the delegated subdomain (e.g., ns1.shop.example.com), the parent zone must also include "glue" A records or AAAA records to avoid circular lookups.

A zone file is a text file containing all resource records for that zone. Zone data is replicated from a primary (master) server to secondary (slave) servers through zone transfers: AXFR (full) or IXFR (incremental), triggered when the SOA serial number changes or via NOTIFY messages.

Example: example.com is one zone; if you create NS records pointing shop.example.com to different nameservers, shop.example.com becomes a separate zone with its own SOA record and zone file.

WarningAlways increment the SOA serial number after editing a zone file. Secondary nameservers compare serial numbers to decide whether to pull updates; if you forget to increment, secondaries will serve stale records indefinitely.

Modern zones can be signed with DNSSEC to cryptographically prove the authenticity of zone records.

Related terms

See it in context

InfraNest shows you your own records, zones and certificates, so the terms stop being abstract.

Free plan · No credit card required · Set up in minutes