Skip to content

DNS Management

enconf integrates PowerDNS as an authoritative DNS server. DNS management allows you to create and edit zones and records directly in the panel.


Overview

DNS management is divided into two areas:

  1. Zones — List of all DNS zones
  2. Records — Detail view of a zone with all DNS entries

DNS Zone Table

Column Description
Zone DNS zone name (e.g. example.com.)
Type Zone type (Native, Master, Slave)
Serial SOA serial number
Customer Assigned customer
Created Creation date

Create Zone

New DNS zones are automatically created when adding a domain. Manual creation is also possible:

  1. Click Create Zone
  2. Fill out the form:
Field Required Description
Zone Name Yes Domain name (e.g. example.com)
Customer Yes (Admin) Assignment to a customer
Type Yes Native (default), Master, or Slave
  1. Click Create

The system automatically creates the default records:

  • SOA — Start of Authority
  • NS — Nameserver entries
  • A — IPv4 address of the server
  • AAAA — IPv6 address (if configured)
  • MX — Mail Exchanger (if email is enabled)

Manage Records

Click on a zone to open the record detail view.

Supported Record Types

Type Description Example
A IPv4 address 93.184.216.34
AAAA IPv6 address 2606:2800:220:1:248:1893:25c8:1946
CNAME Alias to another hostname www.example.com > example.com
MX Mail server 10 mail.example.com
TXT Text record (SPF, DKIM, DMARC) v=spf1 ip4:93.184.216.34 -all
SRV Service record _sip._tcp 0 5 5060 sip.example.com
NS Nameserver ns1.example.com
CAA Certificate Authority Authorization 0 issue "letsencrypt.org"
PTR Reverse DNS 34.216.184.93.in-addr.arpa
SOA Start of Authority Automatically managed

Add Record

  1. Click Add Record
  2. Fill out the form:
Field Required Description
Name Yes Hostname (e.g. www, mail, @ for zone root)
Type Yes Select record type
Content Yes Record value
TTL Yes Time to Live in seconds (default: 3600)
Priority MX/SRV only Priority value
  1. Click Add

TTL Recommendations

  • Default: 3600 (1 hour)
  • Frequently changed: 300 (5 minutes)
  • Rarely changed: 86400 (24 hours)

Edit Record

  1. Click the Edit icon next to a record
  2. Change name, type, content, or TTL
  3. Click Save

Delete Record

  1. Click the Delete icon
  2. Confirm the deletion

System-Critical Records

Do not delete SOA or NS records, as this will affect DNS resolution for the entire zone.


Email Security (DNS)

The Email Security tab in DNS management provides an overview of email-related DNS records:

SPF (Sender Policy Framework)

  • Defines which servers are allowed to send emails for the domain
  • Created as a TXT record
  • Example: v=spf1 ip4:SERVER_IP mx -all

DKIM (DomainKeys Identified Mail)

  • Digital signature for outgoing emails
  • Automatically created as a TXT record
  • Key generation via domain management

DMARC (Domain-based Message Authentication)

  • Policy for handling failed SPF/DKIM checks
  • Created as a TXT record under _dmarc.domain.com
  • Example: v=DMARC1; p=quarantine; rua=mailto:postmaster@domain.com

Maximize Email Deliverability

Always configure all three mechanisms (SPF + DKIM + DMARC) for maximum email deliverability.


DNSSEC

DNSSEC (DNS Security Extensions) protects DNS responses from manipulation and spoofing through digital signatures.

Enable DNSSEC

  1. Open a DNS zone
  2. Navigate to the DNSSEC tab
  3. Click Enable DNSSEC

The system automatically runs: - pdnsutil secure-zone <zone> to generate keys - Generation of KSK (Key Signing Key) and ZSK (Zone Signing Key)

Register DS Records with Your Registrar

After activation, the DS records are displayed. You must register these with your domain registrar:

Field Description
Key Tag Identification number of the key
Algorithm Cryptographic algorithm (e.g., ECDSA 256)
Digest Type Hash algorithm (SHA-256, SHA-384)
Digest Hash value of the KSK

DS Records at Registrar

DNSSEC is only fully active once the DS records are registered with the parent nameserver (registrar). Without DS records, DNSSEC will not be validated.

Disable DNSSEC

  1. Open the DNS zone
  2. Navigate to the DNSSEC tab
  3. Click Disable DNSSEC

Remove DS Records First

Remove the DS records from your registrar before disabling DNSSEC. Otherwise the domain will become unreachable.

Requirements

  • PowerDNS must be configured with gsqlite3-dnssec=yes (SQLite) or gpgsql-dnssec=yes (PostgreSQL)
  • On new installations this setting is configured automatically

Hidden Primary / Zone Transfer

For a hidden-primary setup, enconf runs PowerDNS as a hidden primary: the zone is not published by the enconf server directly, but delivered to your own DNS infrastructure (the public secondaries) via zone transfer (AXFR) and kept in sync via NOTIFY.

Configuration is per zone in the Hidden Primary / Zone Transfer section of the zone detail view — no manual PowerDNS editing required.

Settings

Field Description
Zone transfer active Switches the zone to Master and enables AXFR + NOTIFY
Allow AXFR from IP addresses or CIDR ranges of the secondaries allowed to pull the zone via AXFR (ALLOW-AXFR-FROM)
Send NOTIFY to IP addresses of the secondaries notified on changes (ALSO-NOTIFY)
Public nameservers (NS) External NS hostnames that appear as the zone's NS records. They replace the panel's default nameservers so the enconf server stays hidden. Three or more nameservers are supported.
SOA primary (MNAME) Primary nameserver in the SOA record (default: first configured nameserver)
SOA hostmaster Responsible address in the SOA record (default: hostmaster.<zone>)

Setup

  1. Open the zone and the Hidden Primary / Zone Transfer section.
  2. Under Public nameservers, enter your external NS hostnames (e.g. ns1.provider.com, ns2.provider.com, ns3.provider.com).
  3. Adjust SOA primary and SOA hostmaster if needed.
  4. Enable Zone transfer and add the AXFR and NOTIFY targets of your secondaries.
  5. Click Save.

enconf then switches the zone to Master, stores the AXFR/NOTIFY grants as PowerDNS zone metadata, and sends a NOTIFY to your secondaries.

Change-safe

These settings are stored as PowerDNS zone metadata and are preserved across panel actions such as "Update SOA & NS" or an IP change — your hidden-primary configuration is not overwritten.

Reachability

Your secondaries must be able to reach the enconf server via AXFR over port 53/TCP. Without matching Allow AXFR from entries, PowerDNS refuses the zone transfer.


Synchronize Zone

Click Synchronize to reconcile the zone data with PowerDNS. This is useful when records have been changed directly in PowerDNS.


Delete Zone

  1. Click the Delete icon in the zone list
  2. Confirm the deletion

All Records Will Be Deleted

When deleting a zone, all associated DNS records are permanently removed.