DNS
Host your customers' DNS on the server with PowerDNS: zones and records, DNSSEC, your own nameservers, a DNS cluster with TSIG-signed transfers, and Cloudflare-aware logging.
ZoPanel can run an authoritative DNS server (PowerDNS) so that you and your customers manage zones next to the websites that use them. Hosting DNS here is optional, but it is required for wildcard SSL certificates.
Install the DNS server (administrator)
- Decide on your nameserver names, for example
ns1.yourcompany.comandns2.yourcompany.com. - At the registrar of
yourcompany.com, create glue records (host records) for those names pointing to this server's IP. - In ZoPanel, open DNS, enter the Nameservers (1 to 6 names, separated by commas) and click Install DNS server. You can also install it from Components.
The installer opens port 53 (TCP and UDP) in the firewall. If the DNS server stops answering, the DNS page shows DNS server not answering.
Create a zone
- On the DNS page, in DNS zones, Choose a domain from your websites and click Add zone. A zone can only be created for a domain that has a website in the account.
- At the domain's registrar, set the nameservers shown under Nameservers to set at the registrar.
A new zone already contains:
| Name | Type | Value |
|---|---|---|
@ |
A | the server IP (or the account's dedicated IP) |
www |
A | the same IP |
@ |
CAA | 0 issue "letsencrypt.org" |
| MX, SPF, DKIM, DMARC | added when email is already enabled for the domain |
The CAA record allows only Let's Encrypt to issue certificates for the domain. If you buy a certificate from another authority, add a CAA record for it first.
Edit records
Open a zone to edit its records in a table: Name, Type, Priority, Value and TTL. Click Add record, then Save to apply all changes at once.
| Type | Value format | Example |
|---|---|---|
| A | IPv4 address | 203.0.113.10 |
| AAAA | IPv6 address | 2001:db8::10 |
| CNAME | host name | shop.example.net |
| MX | host name, with Priority | mail.example.com, priority 10 |
| TXT | text | v=spf1 mx a ~all |
| SRV | weight port target, with Priority |
5 5060 sip.example.com |
| CAA | flags tag "value" (tag issue, issuewild or iodef) |
0 issue "letsencrypt.org" |
| NS | host name (delegates a subdomain) | ns1.other-dns.com |
Rules:
- Use
@for the zone apex and relative names (www,mail) for the rest. - NS and CNAME records are not allowed at the apex.
- TTL is between 60 and 604800 seconds; the default is 3600.
The SOA record and the zone's own NS records are managed by ZoPanel and are not shown.
DNSSEC
DNSSEC signs the zone so resolvers can detect spoofed answers.
- Open the zone and turn on DNSSEC.
- Copy the DS record(s) for the registrar shown below the switch.
- Add them at the domain's registrar (usually under "DNSSEC" or "DS records").
To turn DNSSEC off later, remove the DS records at the registrar first and wait for their TTL to expire, then turn the switch off. Otherwise resolvers treat the domain as broken.
Wildcard SSL
With the zone hosted and delegated here, a website can get a *.example.com certificate: tick Also *.example.com (wildcard) on the website's SSL tab. See SSL certificates.
DNS cluster (administrator)
Serve your zones from several ZoPanel servers so DNS keeps answering if one server is down. The DNS cluster card on the DNS page has three settings:
| Setting | Meaning |
|---|---|
| Secondary servers (IPs) | Servers allowed to transfer every zone of this server. They are notified (NOTIFY) of each change. |
| Primary servers | One line per primary: its IP and this server's nameserver name in its zones, for example 203.0.113.10 ns2.example.com. Zones of the primaries are received automatically. |
| Cluster key (TSIG) | A shared key (HMAC-SHA256) that signs zone transfers. |
Recommended setup for two servers:
- On the primary, click Generate next to Cluster key (TSIG) and copy the key: it is not shown again.
- On the primary, add the secondary's IP to Secondary servers (IPs) and Save.
- On the secondary, paste the same key, add the primary to Primary servers and Save.
- Make sure the secondary's nameserver name (the one you entered on the secondary, for example
ns2.example.com) is among the nameservers set at each domain's registrar, with a glue record pointing to the secondary.
With a key, a primary serves its zones only to holders of the key, and a secondary only accepts zones signed with it, so nobody on the path can alter them. Without a key (No key: transfers allowed by address), transfers are allowed by IP address only.
Deleting a zone on the primary does not delete it on the secondaries immediately. A secondary removes a zone its primaries no longer serve after three daily checks in a row; unreachable primaries change nothing. The card lists the zones received from primaries.
Importing zones
When you migrate an account from cPanel or DirectAdmin with Migrate in, its DNS zones are imported too, as long as the DNS server is installed here. ZoPanel's own web, mail (MX, SPF) and CAA records win, other records from the old zone are kept, and a zone that already exists on this server is left untouched. Without the DNS server, zones stay with the old provider and the import log says so.
To copy a zone from any other provider, create the zone here and add its records in the editor before you switch nameservers.
Websites behind Cloudflare
ZoPanel does not manage Cloudflare DNS. If you proxy websites through Cloudflare, turn on Websites behind Cloudflare in Security: ZoPanel then takes the visitor's IP from the CF-Connecting-IP header, trusted only from Cloudflare's address ranges, so logs, statistics, rate limits and Fail2ban see real visitors.
Automatic SSL waits until a domain resolves only to this server, so a domain proxied by Cloudflare is not picked up automatically. Use Issue certificate on the website's SSL tab, or install a certificate in Custom certificate (for example a Cloudflare Origin certificate).