Skip to content
Cloud platformDNS hostingCapabilities verified

Hetzner DNS

Migrate DNS zones to or from Hetzner DNS: what's supported, what access you need, and what changes for each destination.

See how a domain's records would land at Hetzner. Free and read-only.

Access we need

Credentials
Hetzner Cloud API token (per project)
Permissions
A Read token for the preview; a Read & Write token to apply.
Hetzner API documentation

What Hetzner supports

The same data the translation engine uses when it plans a migration.

Create zones through the API
List zones through the API
Turn on DNSSEC through the API
Apex CNAME (flattening)
Apex ALIAS record
Aliases to cloud resources
CDN proxy on records
Routing policies
Minimum TTL
60s

Record types

  • A
  • AAAA
  • CNAME
  • MX
  • TXT
  • NS
  • SRV
  • CAA
  • PTR
  • DS
  • HTTPS
  • SVCB
  • TLSA
  • RP

Good to know

  • Uses the Hetzner Console (Cloud API) DNS. The old DNS Console at dns.hetzner.com and its API were shut down in May 2026.
  • The Cloud API has no DNSSEC signing, so turn DNSSEC off at the registrar before switching nameservers.
  • Only registrable domains can be zones. Subdomains such as dev.example.com can't be their own zone.