Reference
DNSControl parity
Compare DNSControl features with DNSMigrator, including providers, commands, JavaScript functions, record builders, modifiers, export behavior, and gaps.
14 min read
On this page
DNSControl feature parity in DNSMigrator maps dnscontrol get-zones, dnscontrol preview, and dnscontrol push to provider imports, live managed-zone plans, and typed-confirmation pushes. The tables below identify the exact UI, CLI command, implementation, or documented gap for each DNSControl surface.
DNSControl feature parity scope and implementation map#
Only paths reachable from the current web app or dnsmigrator CLI are marked supported here.
| Area | DNSMigrator surface | Implementation |
|---|---|---|
| JavaScript import | Zone → Config as code → Load from dnsconfig.js; Add zone → dnsconfig.js | packages/core/src/features/dnsconfig/runtime.ts |
| JavaScript export | Zone → Config as code; CLI export --format dnsconfig | packages/core/src/features/dnsconfig/export.ts |
| Record construction | Importer and managed-zone editor | packages/core/src/features/records.ts |
| Ignore rules | Zone → Settings → Ignore rules | packages/core/src/features/ignore.ts |
| Builders | Zone → Records → Use a builder | packages/core/src/features/builders/ |
| Transforms and reverse zones | Importer; zone settings; generated plans | packages/core/src/features/transform.ts |
| Provider plans and push | Zone → Preview changes → Changes | packages/core/src/features/plan.ts, packages/services/src/zones.ts |
| One-time migration | New migration | packages/services/src/migrations.ts, packages/services/src/handlers/ |
Status terms: Supported means the construct changes the imported canonical model or a reachable plan. Import-only means script logic runs while converting but has no independent UI control. Preserved-only means metadata round-trips but does not cause a provider operation. Unavailable means the browser runtime rejects it or there is no matching operation.
Providers#
The generated table is the catalog source of truth for DNS and registrar roles, status and capabilities. Provider-specific setup pages use the catalog slug.
72 providers
| Provider | DNS | Registrar | DNSControl id | Authentication |
|---|---|---|---|---|
| Akamai Cloud (Linode) DNScloud | beta | — | LINODE | Personal access token |
| Akamai Edge DNScdn | beta | — | AKAMAIEDGEDNS | EdgeGrid API client (host, client token, client secret, access token) |
| Amazon Route 53cloud | stable | beta | ROUTE53 | Cross-account IAM role with an external ID |
| Azure DNScloud | stable | — | AZURE_DNS | Service principal (client ID + secret) |
| BIND zone filefile | stable | — | BIND | Upload or paste an RFC 1035 zone file |
| Bunny DNScdn | beta | — | BUNNY_DNS | Account API key |
| Cloudflare DNScloud | stable | — | CLOUDFLAREAPI | Scoped API token |
| ClouDNShosting | beta | beta | CLOUDNS | API user auth ID (or sub-user ID/name) + password |
| deSEChosting | beta | — | DESEC | API token |
| DigitalOcean DNScloud | beta | — | DIGITALOCEAN | Personal access token (custom scopes) |
| DNS Made Easyhosting | beta | — | DNSMADEEASY | API key + secret key (HMAC-SHA1 signed requests) |
| DNSimpleregistrar | beta | beta | DNSIMPLE | Account API access token |
| Gandi LiveDNSregistrar | beta | beta | GANDI_V5 | Personal access token (legacy API key also accepted) |
| GoDaddy DNSregistrar | stable | beta | — | Production API key + secret |
| Google Cloud DNScloud | stable | — | GCLOUD | Service account key (JSON) |
| Hetzner DNScloud | beta | — | HETZNER_V2 | Hetzner Cloud API token (per project) |
| Hurricane Electric DNShosting | planned | — | HEDNS | Account username + password (+ TOTP) |
| IBM NS1 Connecthosting | beta | — | NS1 | API key |
| Name.comregistrar | beta | beta | NAMEDOTCOM | Username + API token (Core API, HTTP Basic) |
| Namecheap BasicDNSregistrar | stable | beta | NAMECHEAP | API user + API key, with our egress IP allow-listed |
| Netlify DNScdn | beta | — | NETLIFY | Personal access token |
| Oracle Cloud DNScloud | beta | — | ORACLE | API signing key (tenancy, user, fingerprint, key) |
| OVHcloud DNSregistrar | beta | beta | OVH | Application key + application secret + consumer key (EU, CA or US API) |
| Porkbunregistrar | beta | beta | PORKBUN | API key + secret API key |
| PowerDNS Authoritativeself hosted | beta | — | POWERDNS | API URL + API key (X-API-Key) + server ID |
| Vercel DNScdn | beta | — | VERCEL | Access token (+ team ID) |
| Vultr DNScloud | beta | — | VULTR | API key (personal access token) |
| AdGuard Homeself hosted | beta | — | ADGUARDHOME | Server URL + web interface username + password (HTTP Basic) |
| Alibaba Cloud DNScloud | beta | — | ALIDNS | RAM user AccessKey |
| AutoDNS (InterNetX)registrar | beta | beta | AUTODNS | API user + password + context (Basic auth), optional TOTP 2FA secret |
| Azure Private DNScloud | beta | — | AZURE_PRIVATE_DNS | Service principal (client ID + secret) |
| CentralNic Resellerregistrar | beta | beta | CNR | Reseller (or sub-user) login + password over the HTTPS gateway |
| CSC Global Domain Managerregistrar | beta | beta | CSCGLOBAL | API key + bearer (user) token |
| DNS over HTTPS (read-only)registrar | — | beta | DNSOVERHTTPS | None: reads nameservers through public DNS |
| DNScalehosting | beta | — | DNSCALE | Zone-scopable API key (Bearer) |
| Domeneshopregistrar | beta | — | DOMAINNAMESHOP | API token + secret (HTTP Basic) |
| Dynadotregistrar | — | beta | DYNADOT | API key |
| Dynuhosting | beta | — | DYNU | API key (API-Key header) |
| easynameregistrar | — | beta | EASYNAME | User ID + email + API key + signing salt |
| Exoscale DNScloud | beta | — | EXOSCALE | IAM API key + secret |
| FortiGate DNSself hosted | beta | — | FORTIGATE | Management URL + REST API admin token (Bearer) + VDOM |
| Gcore DNScdn | beta | — | GCORE | Permanent API token |
| GidiNETregistrar | beta | beta | GIDINET | Username + dedicated API password (SOAP) |
| Gigahosthosting | beta | — | GIGAHOST | Personal API key (Bearer flux_live_…) |
| hosting.deregistrar | beta | beta | HOSTINGDE | API key (authToken), optional sub-account ID |
| Huawei Cloud DNScloud | beta | — | HUAWEICLOUD | IAM access key (AK) + secret key (SK) |
| IBM Cloud Classic (SoftLayer) DNScloud | beta | — | SOFTLAYER | Classic infrastructure username + API key |
| Infomaniak DNShosting | beta | — | INFOMANIAK | API token (OAuth2 Bearer) with scopes |
| Internet.bsregistrar | — | beta | INTERNETBS | API key + password |
| INWXregistrar | beta | beta | INWX | Username + password session login, with optional TOTP 2FA secret |
| Joker.comregistrar | beta | — | JOKER | DMAPI API key (or username + password), session-based |
| Loopiaregistrar | beta | beta | LOOPIA | LoopiaAPI username + password |
| LuaDNShosting | beta | — | LUADNS | Account email + API key (HTTP Basic) |
| MikroTik RouterOSself hosted | beta | — | MIKROTIK | RouterOS REST API URL + username + password (HTTP Basic, RouterOS v7.1+) |
| Mythic Beastshosting | beta | — | MYTHICBEASTS | API key ID + secret (DNS API v2) |
| NetBirdself hosted | beta | — | NETBIRD | Personal access token (Authorization: Token) + optional self-hosted management URL |
| netcuphosting | beta | — | NETCUP | Customer number + API key + API password (CCP API session) |
| Netnod Primary DNShosting | beta | — | NETNOD | API token (Authorization: Token) |
| NexDNShosting | beta | — | NEXDNS | API key (Bearer, nxd_ prefix) |
| NextDNS rewriteshosting | beta | — | — | API key + profile ID |
| OpenSRSregistrar | — | beta | OPENSRS | Reseller username + API key |
| OpenWrtself hosted | beta | — | OPENWRT | LuCI URL + username + password (LuCI JSON-RPC, luci-mod-rpc) |
| Packetframehosting | beta | — | PACKETFRAME | Account session token (Authorization: Token) |
| Realtime Registerregistrar | beta | beta | REALTIMEREGISTER | API key (Authorization: ApiKey) |
| RFC 2136 dynamic DNS (AXFR + DDNS)self hosted | beta | — | AXFRDDNS | Primary server + TSIG key (HMAC-SHA256/512; SHA1/MD5 for legacy servers) |
| RWTH Aachen DNS-Adminhosting | beta | — | RWTH | DNS-Admin API token (PRIVATE-TOKEN header) |
| Sakura Cloud DNScloud | beta | — | SAKURACLOUD | API key (access token + access token secret) |
| Scaleway Domains and DNScloud | beta | — | SCALEWAY | IAM API secret key (+ optional project ID) |
| Tencent Cloud DNSPodcloud | beta | beta | TENCENTDNS | CAM SecretId + SecretKey |
| TransIPregistrar | beta | — | TRANSIP | Username + API private key (signed JWT), or an access token |
| UniFi Networkself hosted | beta | — | UNIFI | API key (X-API-Key) + controller URL or UniFi console ID (via api.ui.com) |
| Websupporthosting | beta | — | WEBSUPPORT | API key + secret (HMAC-SHA1 signed requests) |
Hurricane Electric is cataloged but planned because DNSControl automates its web UI with account credentials and a TOTP seed rather than an official API. GoDaddy remains available even though current DNSControl no longer includes it. DNSMigrator also has providers beyond DNSControl, including NextDNS rewrites.
DNSControl get-zones, preview, and push#
| DNSControl command or file | Status | DNSMigrator equivalent |
|---|---|---|
preview | Supported | Managed zone: Preview changes → Changes. Migration: Create preview. Both read live state and produce a plan without record writes. |
push | Supported | Managed zone: type the zone name, then Push to N providers. Migration: Apply N changes. Both re-read live destination state and calculate the operations used for the write. |
check-creds | Supported | Creating a connection runs verification; Connections → Check access runs it again and records read or write scope. |
get-zones | Supported in UI | Zones → Add zone → Import from a provider, or select a connected source under New migration. BIND and dnsconfig.js output are available after import or through CLI export; the credential-free CLI does not fetch provider zones. |
init | UI equivalent | Connect a provider, then Add zone. The app does not write local creds.json or dnsconfig.js files. |
fmt | Partial equivalent | Zone file validator and CLI export --format bind normalize BIND. DNSMigrator does not reformat arbitrary JavaScript. |
check | Supported | Managed-zone Zone checks and CLI dnsmigrator lint. |
print-ir | Supported | CLI dnsmigrator export --format json emits the canonical zone model. |
creds.json | Deliberately replaced | Create encrypted workspace Connections. Credential files are not imported or exported. |
--domains / --providers selection | UI equivalent | Open one managed zone and attach its providers under Settings → Providers. |
--variable / CLI_DEFAULTS | Partial | CLI_DEFAULTS is parsed, but the current import screen has no variable input; missing variables produce a warning. |
--notify | UI equivalent | Configure workspace Notifications; pushes, drift, cutover and failures dispatch through those channels. |
--expect-no-changes | UI and CLI equivalents | Check for drift for managed zones, or dnsmigrator diff --strict for files. |
--no-populate | No direct switch | Managed preview does not create zones; push/apply can create a missing destination zone. |
--report | Supported by related surfaces | Migration Report pages, CLI JSON, and translate --report. |
--help, --version, color flags | CLI equivalent | dnsmigrator --help, --version, --no-color, and NO_COLOR. |
DNSControl’s removed ppreview and ppush aliases do not need equivalents. DNSMigrator does not expose DNSControl’s --cmode modes; managed-zone provider writes run sequentially.
Top-level JavaScript functions#
| Function | Status | Behavior in DNSMigrator |
|---|---|---|
D | Supported | Declares one desired zone; tags after ! are retained. |
D_EXTEND | Supported, import-only | Adds modifiers to the closest previously declared parent zone and handles subdomain context. |
DEFAULTS | Supported, import-only | Applies default domain modifiers to later D declarations until replaced. |
DOMAIN_ELSEWHERE | Supported | Creates a no-purge zone with explicit nameservers. |
DOMAIN_ELSEWHERE_AUTO | Supported | Creates a no-purge zone and attaches declared DNS providers. |
NewDnsProvider | Supported | Declares a key and resolves its DNSControl type, catalog ID, slug, or inferred name for later connection mapping. No secrets are read. |
NewRegistrar | Partial | Parses and retains registrar identity, but the importer has no registrar-connection mapping control. Select Registrar account in the imported zone’s settings; no secrets are read. |
IP | Supported, import-only | Converts a valid dotted IPv4 address to its integer form for transform tables. |
REV | Supported | Generates IPv4 or IPv6 reverse-zone names, including classless forms. |
REVCOMPAT | Supported, import-only | Selects RFC 2317 or RFC 4183 reverse naming once per evaluation. |
PANIC | Supported, import-only | Aborts import with the supplied message. |
getConfiguredDomains | Supported, import-only | Returns declarations seen so far for script logic. |
INCLUDE | Supported, import-only | Copies records from a previously declared zone. |
CLI_DEFAULTS | Partial | Warns for variable names not supplied to the runtime; the web screen does not collect values. |
require | Unavailable | Rejected because the browser worker cannot read modules or files. |
require_glob | Unavailable | Rejected because the browser worker cannot enumerate files. |
glob | Unavailable | Rejected in the browser runtime. |
FETCH | Unavailable | Rejected because importer evaluation has no network access. |
fetch | Unavailable | Lowercase compatibility alias is also rejected. |
HASH | Unavailable | Rejected in the browser runtime. |
Standard record functions#
All rows below are accepted by the browser importer and represented in the canonical zone model. The managed record editor uses structured forms for provider-supported types. A later provider plan can still mark a record unsupported.
| Function | Canonical result | Planning note |
|---|---|---|
A | A | IPv4 is validated and canonicalized. |
AAAA | AAAA | IPv6 is validated and canonicalized. |
ALIAS | ALIAS | Retained as a canonical ALIAS for managed-zone planning. The one-time migration translator can convert it to a destination-native alias, apex CNAME, or supplied static addresses. |
CAA | CAA | Valid tags are checked; CAA_CRITICAL sets flag 128. |
CNAME | CNAME | Targets are fully qualified; coexistence is linted. |
DHCID | DHCID | One value is retained. |
DNAME | DNAME | Target is normalized as a hostname. |
DNSKEY | DNSKEY | Accepted on import but provider-managed DNSKEY sets are omitted from normal plans. |
DS | DS | Child-delegation DS data remains a normal record set. Registrar apex DS changes belong to cutover. |
FRAME | FRAME | Provider redirect feature; blocked when the destination has no equivalent. |
HTTPS | HTTPS | Priority and target are normalized; alias mode omits parameters, while other parameter text is retained. |
LOC | LOC | Coordinates and precision fields become canonical LOC presentation text. |
MX | MX | Priority is range-checked and target is fully qualified. |
NAPTR | NAPTR | Order, preference, flags, service, regexp and replacement are retained. |
NS | NS | Non-apex delegation records are planned normally; apex NS is managed through nameserver settings. |
OPENPGPKEY | OPENPGPKEY | Valid hexadecimal input is converted to base64; valid base64 is retained. |
PTR | PTR | Reverse-zone label handling honors REVCOMPAT. |
RP | RP | Mailbox and TXT-domain targets are normalized. |
SMIMEA | SMIMEA | Numeric fields are checked and association data is canonicalized. |
SOA | SOA | Accepted and exportable, but normal provider plans treat SOA as provider-managed. |
SRV | SRV | Priority, weight and port are checked; target is fully qualified or .. |
SSHFP | SSHFP | Algorithm and fingerprint type are checked; fingerprint is uppercased. |
SVCB | SVCB | Priority and target are normalized; alias mode omits parameters, while other parameter text is retained. |
TLSA | TLSA | Usage, selector and matching type are checked; association data is canonicalized. |
TXT | TXT | Multiple JavaScript arguments are concatenated into one logical TXT value. |
URL | URL | Provider redirect feature; blocked where no equivalent exists. |
URL301 | URL301 | Permanent provider redirect feature; blocked where no equivalent exists. |
The canonical model also understands obsolete SPF record sets from BIND/provider input. The importer’s DNSControl-style DSL creates SPF policy data through TXT or SPF_BUILDER, and exports obsolete SPF as TXT with a warning.
Provider-specific record functions#
| Function | Status and location |
|---|---|
ADGUARDHOME_A_PASSTHROUGH | Supported for AdGuard Home rewrite semantics. |
ADGUARDHOME_AAAA_PASSTHROUGH | Supported for AdGuard Home IPv6 passthrough semantics. |
AKAMAICDN | Supported Akamai Edge DNS provider feature. |
AKAMAITLC | Supported Akamai traffic-management target with DUAL, A, or AAAA answer mode. |
R53_ALIAS | Supported Route 53 resource/hostname alias; stores DNS name, hosted-zone ID and evaluate-target-health metadata. |
AZURE_ALIAS | Supported Azure resource alias for A, AAAA, or CNAME. |
CF_REDIRECT | Supported Cloudflare bulk redirect feature; canonical owner is the zone apex. |
CF_TEMP_REDIRECT | Supported Cloudflare temporary redirect feature. |
CF_SINGLE_REDIRECT | Supported Cloudflare single redirect with accepted HTTP redirect codes. |
CF_WORKER_ROUTE | Supported Cloudflare Worker route feature. |
CLOUDNS_WR | Supported ClouDNS web redirect feature. |
MIKROTIK_FORWARDER | Supported MikroTik forwarder feature. |
MIKROTIK_FWD | Supported MikroTik forwarding entry. |
MIKROTIK_NXDOMAIN | Supported MikroTik NXDOMAIN entry. |
LUA | Supported PowerDNS LUA record with emitted record type and expression. |
BUNNY_DNS_PZ | Accepted for compatibility, then skipped during import with a warning; it has no release canonical record type or exporter case. |
BUNNY_DNS_RDR | Accepted for compatibility, then skipped during import with a warning; it has no release canonical record type or exporter case. |
PORKBUN_URLFWD | Accepted for compatibility, then skipped during import with a warning; it has no release canonical record type or exporter case. |
Supported provider features are not portable DNS. During migration, translateZone blocks one when the destination catalog does not advertise the same type and explains that it must be recreated manually. The Bunny and Porkbun compatibility-only functions above are skipped before they reach translation.
Domain modifiers and nameservers#
| Modifier | Status | DNSMigrator mapping |
|---|---|---|
DnsProvider | Supported | Attaches a declared provider and optional nameserver count; map its key to a Connection during import. |
DefaultTTL | Supported | Saves the zone default used for records without an explicit positive TTL. |
NAMESERVER | Supported | Adds explicit apex nameservers alongside attached providers’ nameservers. |
NAMESERVER_TTL | Supported | Saves the TTL used for the planned apex NS set. |
NO_PURGE | Supported | Never delete records at the provider on; provider-only records remain. |
PURGE | Supported | Never delete records at the provider off; exact desired-state planning may delete extras. |
AUTODNSSEC_ON | Supported where the adapter can toggle DNSSEC | DNSSEC → Sign; lint warns for attached providers without automatic DNSSEC. |
AUTODNSSEC_OFF | Supported where the adapter can toggle DNSSEC | DNSSEC → Unsign. Registrar DS handling is still a separate cutover concern. |
AUTODNSSEC | Deprecated no-op | Imported with a warning; use the explicit forms. |
IGNORE | Supported | Adds name, type and target glob matching. |
IGNORE_NAME | Supported | Convenience form for name and optional type matching. |
IGNORE_TARGET | Supported | Convenience form for target and optional type matching. |
IGNORE_EXTERNAL_DNS | Supported | Preserves records identified by external-dns ownership TXT data; optional prefix is retained. |
DISABLE_IGNORE_SAFETY_CHECK | Supported | Allows a configured record to also match an ignore rule, with a warning. |
IGNORE_NAME_DISABLE_SAFETY_CHECK | Unavailable | Rejected with instructions to use the domain-wide replacement. |
IMPORT_TRANSFORM | Supported | At plan time, derives A and CNAME records from another managed zone and applies IPv4 mappings. |
IMPORT_TRANSFORM_STRIP | Supported | Same, with source suffix removal. |
GIDINET_PREMIUM_NS | Supported, import-only | Expands to the five GidiNET premium nameserver declarations. |
Managed-zone planning combines explicit nameservers with provider nameservers returned when a destination zone is created, honoring each configured nameserver count. Existing provider-managed apex NS records are otherwise excluded from ordinary plans. See Multi-provider DNS and Import transforms.
Builders#
Each builder is available under Records → Use a builder and through dnsconfig.js import.
| Builder | Result |
|---|---|
SPF_BUILDER | Builds an SPF TXT policy, can flatten selected includes when a resolver is available, can split overflow into a %d chain, and warns over the SPF lookup limit. |
DMARC_BUILDER | Builds _dmarc TXT with validated policies, alignments, report URIs, failure options and supported extension tags. |
CAA_BUILDER | Builds CAA sets for issue, issuewild, issuevmc, issuemail and optional iodef, including critical flags. |
DKIM_BUILDER | Builds selector _domainkey TXT for RSA or Ed25519 with validated hash, service and flag values. |
M365_BUILDER | Builds selected Microsoft 365 MX, Autodiscover, DKIM, Teams/Skype and enrollment records; SPF is a DNSMigrator extension. |
LOC_BUILDER_DD | Builds LOC from decimal latitude and longitude. |
LOC_BUILDER_DMM_STR | Builds LOC from degrees and decimal-minutes text. |
LOC_BUILDER_DMS_STR | Builds LOC from degrees, minutes and seconds text. |
LOC_BUILDER_STR | Accepts either supported coordinate text form. |
Browser config import has no DNS resolver, so imported SPF flattening remains unflattened with a warning. The managed-zone SPF builder calls the app’s TXT resolver and can flatten there.
Record modifiers and compatibility constants#
| Modifier or constant | Status | Behavior |
|---|---|---|
TTL | Supported | Parses seconds or s, m, h, d, w, n, and y duration suffixes. |
CAA_CRITICAL | Supported | Sets CAA flag 128. |
ENSURE_ABSENT_REC | Supported | Removes a matching value or record even when NO_PURGE is active. |
R53_ZONE | Supported on aliases; preserved at domain level | Supplies an alias hosted-zone ID. Domain use becomes metadata without a provider operation. |
R53_EVALUATE_TARGET_HEALTH | Supported | Stores Route 53 alias health-evaluation intent. |
R53_WEIGHT | Supported | Stores weighted routing, set identifier and validated weight. |
R53_HEALTH_CHECK_ID | Supported | Adds the Route 53 health-check ID to weighted routing metadata. |
HEDNS_DYNAMIC_ON | Import/export compatibility | Stores canonical dynamic metadata. The live Hurricane Electric provider is planned, so this is not currently a web push target. |
HEDNS_DYNAMIC_OFF | Import/export compatibility | Stores canonical non-dynamic metadata; no live HE web push is available. |
HEDNS_DDNS_KEY | Import/export compatibility; secret export redacted | Stores canonical DDNS-key metadata. Normal web export replaces it with HEDNS_DYNAMIC_ON and warns; no live HE web push is available. |
CF_PROXY_ON | Supported | Sets canonical proxied: true. |
CF_PROXY_OFF | Supported | Sets canonical proxied: false. |
CF_PROXY_FULL | Partial | Imports as proxied: true; the distinct “full” value is not retained. |
CF_PROXY_DEFAULT_ON | Supported on import | Applies proxied-by-default to A, AAAA and CNAME records without an explicit setting. |
CF_PROXY_DEFAULT_OFF | Supported as the default state | Retains explicit non-default metadata but does not alter records already marked proxied. |
CF_COMMENT | Partial | Stores canonical comment metadata and includes it when a Cloudflare record is otherwise created or updated; a comment-only difference does not create a plan operation. |
CF_TAGS | Not applied by importer | The current metadata converter reports it as having no equivalent and drops it. |
CF_CNAME_FLATTEN_ON, CF_CNAME_FLATTEN_OFF | Preserved-only at domain level | Kept as zone metadata but do not trigger a Cloudflare operation. |
CF_UNIVERSALSSL_ON, CF_UNIVERSALSSL_OFF | Preserved-only at domain level | Kept as zone metadata but do not trigger a Cloudflare operation. |
CF_MANAGE_COMMENTS, CF_MANAGE_TAGS | Preserved-only at domain level | Kept as zone metadata; provider comparison is capability-driven instead. |
DISABLE_REPEATED_DOMAIN_CHECK | Supported | Allows an intentionally repeated zone suffix on that record. |
AUTOSPLIT | Accepted no-op | Compatibility sentinel; current records are already canonical logical values. |
END | Accepted no-op | Compatibility sentinel. |
DKIM | Supported, import-only | Identity wrapper used around generated record modifiers. |
Arbitrary metadata objects are accepted, but unrecognized record metadata produces a warning and is dropped from the canonical record. Unrecognized domain metadata is retained as strings and re-exported as a JavaScript object.
Export behavior#
The Config as code tab exports the saved zone, not unsaved edits. It generates provider and registrar declarations, domain modifiers, records, ignores, transforms and supported metadata. CLI export --format dnsconfig uses the same generator for one BIND file.
Export deliberately warns about lossy cases:
- non-weighted routing has no emitted DNSControl modifier and is dropped;
- Hurricane Electric DDNS keys are redacted by default;
- obsolete SPF record types become TXT;
- unsupported record types become comments;
- records outside the zone are skipped;
- SOA serial is provider-managed and is dropped;
Generated JavaScript should be reviewed before dnscontrol push. See dnsconfig.js import and export.
Known deviations#
- Glob matching follows DNSControl’s implementation where older documentation differs.
- DMARC and CAA builders reject invalid policy, URI, tag, range and flag input instead of retaining it.
- Names are lowercased but are not converted to IDNA; use ASCII or already-punycode names.
- Provider declarations resolve known DNSControl IDs, catalog IDs, slugs and recognizable key names. An inferred type is reported as a warning so you can verify the mapping.
D_EXTENDandINCLUDErequire the source declaration to appear earlier in the script.- The browser importer preserves JavaScript-generated desired state, not arbitrary JavaScript source formatting or comments.
- Provider capability checks happen after import. A valid DSL function can still be unsupported by an attached provider and will appear in Changes rather than being sent silently.
Features beyond DNSControl#
DNSMigrator adds a separate migration lifecycle with destination snapshots, live destination re-planning, authoritative record verification, operation-scoped rollback, guided or automatic registrar cutover, DNSSEC sequencing, bulk CSV migrations and shareable reports. Managed zones add scheduled backups, restore, drift monitoring, workspace roles and signed notification webhooks. These features are documented by their app workflows rather than represented as extra dnsconfig.js functions.