# DNS

> Host your customers' DNS on the server with PowerDNS: zones and records, DNSSEC, your own nameservers, a DNS cluster with TSIG-signed transfers, and Cloudflare-aware logging.

Source: https://zopanel.net/docs/dns  
Updated: 2026-10-07

ZoPanel can run an authoritative DNS server (PowerDNS) so that you and your customers manage zones next to the websites that use them. Hosting DNS here is optional, but it is required for wildcard SSL certificates.

## Install the DNS server (administrator)

1. Decide on your nameserver names, for example `ns1.yourcompany.com` and `ns2.yourcompany.com`.
2. At the registrar of `yourcompany.com`, create glue records (host records) for those names pointing to this server's IP.
3. In ZoPanel, open **DNS**, enter the **Nameservers** (1 to 6 names, separated by commas) and click **Install DNS server**. You can also install it from **Components**.

The installer opens port 53 (TCP and UDP) in the firewall. If the DNS server stops answering, the DNS page shows **DNS server not answering**.

## Create a zone

1. On the **DNS** page, in **DNS zones**, **Choose a domain** from your websites and click **Add zone**. A zone can only be created for a domain that has a website in the account.
2. At the domain's registrar, set the nameservers shown under **Nameservers to set at the registrar**.

A new zone already contains:

| Name | Type | Value |
| --- | --- | --- |
| `@` | A | the server IP (or the account's dedicated IP) |
| `www` | A | the same IP |
| `@` | CAA | `0 issue "letsencrypt.org"` |
| MX, SPF, DKIM, DMARC | | added when email is already enabled for the domain |

The CAA record allows only Let's Encrypt to issue certificates for the domain. If you buy a certificate from another authority, add a CAA record for it first.

## Edit records

Open a zone to edit its records in a table: **Name**, **Type**, **Priority**, **Value** and **TTL**. Click **Add record**, then **Save** to apply all changes at once.

| Type | Value format | Example |
| --- | --- | --- |
| A | IPv4 address | `203.0.113.10` |
| AAAA | IPv6 address | `2001:db8::10` |
| CNAME | host name | `shop.example.net` |
| MX | host name, with **Priority** | `mail.example.com`, priority `10` |
| TXT | text | `v=spf1 mx a ~all` |
| SRV | `weight port target`, with **Priority** | `5 5060 sip.example.com` |
| CAA | `flags tag "value"` (tag `issue`, `issuewild` or `iodef`) | `0 issue "letsencrypt.org"` |
| NS | host name (delegates a subdomain) | `ns1.other-dns.com` |

Rules:

- Use `@` for the zone apex and relative names (`www`, `mail`) for the rest.
- NS and CNAME records are not allowed at the apex.
- TTL is between 60 and 604800 seconds; the default is 3600.

The SOA record and the zone's own NS records are managed by ZoPanel and are not shown.

## DNSSEC

DNSSEC signs the zone so resolvers can detect spoofed answers.

1. Open the zone and turn on **DNSSEC**.
2. Copy the **DS record(s) for the registrar** shown below the switch.
3. Add them at the domain's registrar (usually under "DNSSEC" or "DS records").

To turn DNSSEC off later, remove the DS records at the registrar first and wait for their TTL to expire, then turn the switch off. Otherwise resolvers treat the domain as broken.

## Wildcard SSL

With the zone hosted and delegated here, a website can get a `*.example.com` certificate: tick **Also \*.example.com (wildcard)** on the website's **SSL** tab. See [SSL certificates](/docs/ssl#wildcard-certificates).

## DNS cluster (administrator)

Serve your zones from several ZoPanel servers so DNS keeps answering if one server is down. The **DNS cluster** card on the DNS page has three settings:

| Setting | Meaning |
| --- | --- |
| **Secondary servers (IPs)** | Servers allowed to transfer every zone of this server. They are notified (NOTIFY) of each change. |
| **Primary servers** | One line per primary: its IP and this server's nameserver name in its zones, for example `203.0.113.10 ns2.example.com`. Zones of the primaries are received automatically. |
| **Cluster key (TSIG)** | A shared key (HMAC-SHA256) that signs zone transfers. |

Recommended setup for two servers:

1. On the primary, click **Generate** next to **Cluster key (TSIG)** and copy the key: it is not shown again.
2. On the primary, add the secondary's IP to **Secondary servers (IPs)** and **Save**.
3. On the secondary, paste the same key, add the primary to **Primary servers** and **Save**.
4. Make sure the secondary's nameserver name (the one you entered on the secondary, for example `ns2.example.com`) is among the nameservers set at each domain's registrar, with a glue record pointing to the secondary.

With a key, a primary serves its zones only to holders of the key, and a secondary only accepts zones signed with it, so nobody on the path can alter them. Without a key (**No key: transfers allowed by address**), transfers are allowed by IP address only.

Deleting a zone on the primary does not delete it on the secondaries immediately. A secondary removes a zone its primaries no longer serve after three daily checks in a row; unreachable primaries change nothing. The card lists the zones received from primaries.

## Importing zones

When you migrate an account from cPanel or DirectAdmin with **Migrate in**, its DNS zones are imported too, as long as the DNS server is installed here. ZoPanel's own web, mail (MX, SPF) and CAA records win, other records from the old zone are kept, and a zone that already exists on this server is left untouched. Without the DNS server, zones stay with the old provider and the import log says so.

To copy a zone from any other provider, create the zone here and add its records in the editor before you switch nameservers.

## Websites behind Cloudflare

ZoPanel does not manage Cloudflare DNS. If you proxy websites through Cloudflare, turn on **Websites behind Cloudflare** in **Security**: ZoPanel then takes the visitor's IP from the `CF-Connecting-IP` header, trusted only from Cloudflare's address ranges, so logs, statistics, rate limits and Fail2ban see real visitors.

Automatic SSL waits until a domain resolves only to this server, so a domain proxied by Cloudflare is not picked up automatically. Use **Issue certificate** on the website's **SSL** tab, or install a certificate in **Custom certificate** (for example a Cloudflare Origin certificate).
