Cloud platformDNS hostingCapabilities verified
Hetzner DNS
Migrate DNS zones to or from Hetzner DNS: what's supported, what access you need, and what changes for each destination.
See how a domain's records would land at Hetzner. Free and read-only.
Access we need
- Credentials
- Hetzner Cloud API token (per project)
- Permissions
- A Read token for the preview; a Read & Write token to apply.
What Hetzner supports
The same data the translation engine uses when it plans a migration.
- Create zones through the API
- List zones through the API
- Turn on DNSSEC through the API
- Apex CNAME (flattening)
- Apex ALIAS record
- Aliases to cloud resources
- CDN proxy on records
- Routing policies
- Minimum TTL
- 60s
Record types
- A
- AAAA
- CNAME
- MX
- TXT
- NS
- SRV
- CAA
- PTR
- DS
- HTTPS
- SVCB
- TLSA
- RP
Good to know
- Uses the Hetzner Console (Cloud API) DNS. The old DNS Console at dns.hetzner.com and its API were shut down in May 2026.
- The Cloud API has no DNSSEC signing, so turn DNSSEC off at the registrar before switching nameservers.
- Only registrable domains can be zones. Subdomains such as dev.example.com can't be their own zone.