---
name: azion-create-edit-or-delete-a-zone
description: >-
  Create, rename, deactivate, or delete an Edge DNS zone in Azion Console, the Azion CLI, or the API, and get the nameservers for your registrar.
---

# Create, edit, or delete a zone

You can create, edit, or delete an [Edge DNS](/en/documentation/platform/edge-dns/) zone from Azion Console, the Azion CLI, or the Azion API. To add or change the records inside a zone, refer to [Add, edit, or delete a record](/en/documentation/guides/application-security/dns/add-records/) instead.

---

Select your interface once. The prerequisites and every task below show only that path.

## Prerequisites

- The **Edit Edge DNS** permission. It grants access to create, edit, and remove zones, and it requires **View Edge DNS**. Refer to [Teams permissions](/en/documentation/fundamentals/teams-permissions/).
- To create a zone, a domain you control that no other zone in Azion hosts.

**Console**

- Access to Azion Console. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**CLI**

- The [Azion CLI](/en/documentation/devtools/cli/) installed and authorized.

**API**

- A [personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/) and `curl`.
- For every endpoint and field of the API, refer to the [Azion API reference](https://api.azion.com/).

---

## Create a zone

A zone holds one domain, and the domain is fixed once the zone exists. Replace `example.com` with your domain in every step.

**Console**

To create the zone in Azion Console:

1. **Open the Edge DNS page**

   Access [Azion Console](https://console.azion.com/) > **Edge DNS**.

2. **Select + Zone**

3. **Name the zone**

   In the **General** section, enter a **Name** of 1 to 50 characters, such as `example-zone`. The name identifies the zone in lists.

4. **Enter the domain**

   In the **Domain Name** section, enter your root domain in **Domain Name**, such as `example.com`.

5. **(Optional) Turn on DNSSEC**

   To sign the zone from the start, turn on **Enable DNSSEC** in the **DNSSEC** section.

6. **Keep Active turned on**

   In the **Status** section, keep **Active** turned on.

7. **Select Create**

The Console opens the zone's **Records** tab and shows `Your DNS zone has been created. To complete the setup, ensure the Azion nameservers are configured in your domain provider.`

To copy the nameservers for your registrar, return to the **Zones** page and select **Copy Nameserver Values**. It copies the three names joined by semicolons. The zone's **Main Settings** tab also lists each one under **Configure your Nameserver**, with a copy button.

**CLI**

To create the zone with the Azion CLI, run:

```bash
azion create dns-zone --name example-zone --domain example.com --active=true
```

The command prints the ID of the zone:

```text
Created DNS zone with ID 1235
```

The zone exists and is active. To read the nameservers for your registrar, describe the zone:

```bash
azion describe dns-zone --zone-id <zone-id>
```

The output lists them under `Nameservers:`:

```text
…
Nameservers:       ["ns1.aziondns.net","ns2.aziondns.com","ns3.aziondns.org"]
…
```

**API**

To create the zone with the Azion API, send a `POST` request to the zones endpoint. Replace `[TOKEN VALUE]` with your personal token:

```bash
curl -X POST https://api.azion.com/v4/workspace/dns/zones \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Content-Type: application/json" \
  -d '{"name":"example-zone","domain":"example.com","active":true}'
```

A `201` returns the zone:

```json
{
  "state": "executed",
  "data": {
    "id": 1234,
    "name": "example-zone",
    "domain": "example.com",
    "active": true,
    "nameservers": ["ns1.aziondns.net", "ns2.aziondns.com", "ns3.aziondns.org"],
    "product_version": "2.0"
  }
}
```

The `nameservers` array lists the three nameservers to set at your registrar. Record the `id`: every later request on the zone uses it.

A domain another zone already hosts is refused. For each refusal and its code, refer to [Zones and records](/en/documentation/platform/edge-dns/zones-and-records/#errors).

The new zone answers only for the records you add to it. Resolvers on the internet ask Azion's nameservers only after you delegate the domain to all three at your registrar: `ns1.aziondns.net`, `ns2.aziondns.com`, and `ns3.aziondns.org`. For the full move, refer to [Migrate nameservers to Azion](/en/documentation/guides/platform/migration/migrate-ns-to-azion/).

---

## Edit a zone

After creation, you can rename a zone, turn it off or back on, and turn DNSSEC on. The domain cannot change: to serve another domain, create another zone.

A zone with **Active** turned off keeps its records, but Azion's nameservers answer its names with `REFUSED`. Like any change, this can take a few minutes to reach every nameserver.

**Console**

To edit the zone in Azion Console:

1. **Open the Edge DNS page**

   Access [Azion Console](https://console.azion.com/) > **Edge DNS**.

2. **Open the zone**

   On the **Zones** page, select the row of the zone. It opens on the **Main Settings** tab, where the **Domain Name** field of the **Domain** section is locked.

3. **(Optional) Rename the zone**

   In the **General** section, enter a new **Name**.

4. **(Optional) Turn the zone off or on**

   In the **Status** section, turn **Active** off to stop answers for the zone, or on to resume them.

5. **(Optional) Turn on DNSSEC**

   In the **DNSSEC** section, turn on **Enable DNSSEC**.

6. **Select Save**

The Console shows `Edge DNS has been updated`, and the zone stays open on **Main Settings**.

After you turn on DNSSEC, reload the page. The **Key Tag**, **Algorithm**, **Digest Type**, and **Digest** fields then show the values your registrar needs, each with a copy button. To give them to your registrar, refer to [Turn on DNSSEC for a zone](/en/documentation/guides/application-security/dns/activate-dnssec/).

The same **Enable DNSSEC** switch turns DNSSEC off. Before you turn it off, follow the order in [Turn DNSSEC off](/en/documentation/guides/application-security/dns/activate-dnssec/#turn-dnssec-off).

**CLI**

To rename the zone with the Azion CLI, pass the new name to `--name`. Replace `<zone-id>` with the ID of your zone:

```bash
azion update dns-zone --zone-id <zone-id> --name example-zone-renamed
```

The command confirms the update:

```text
DNS zone 1236 was updated
```

To turn the zone off, set `--active=false`. To turn it back on, set `--active=true`:

```bash
azion update dns-zone --zone-id <zone-id> --active=false
```

The command confirms the update:

```text
DNS zone 1235 was updated
```

To check the result, run `azion describe dns-zone --zone-id <zone-id>`. It prints the name under `Name:` and the state under `Active:`, which reads `false` for a zone turned off.

DNSSEC has its own command. To turn it on, refer to [Turn on DNSSEC for a zone](/en/documentation/guides/application-security/dns/activate-dnssec/).

**API**

To rename the zone with the Azion API, send a `PATCH` request with the new `name`. Replace `<zone-id>` with the `id` of your zone:

```bash
curl -X PATCH https://api.azion.com/v4/workspace/dns/zones/<zone-id> \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Content-Type: application/json" \
  -d '{"name":"example-zone-renamed"}'
```

A `200` returns the zone with the new name:

```json
{
  "state": "executed",
  "data": {
    "id": 1234,
    "name": "example-zone-renamed",
    "domain": "example.com",
    "active": true,
    "nameservers": ["ns1.aziondns.net", "ns2.aziondns.com", "ns3.aziondns.org"],
    "product_version": "2.0"
  }
}
```

To turn the zone off, send `{"active":false}` in the same request:

```bash
curl -X PATCH https://api.azion.com/v4/workspace/dns/zones/<zone-id> \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Content-Type: application/json" \
  -d '{"active":false}'
```

A `200` returns the zone with `active` set to `false`:

```json
{
  "state": "executed",
  "data": {
    "id": 1237,
    "name": "example-zone",
    "domain": "example.com",
    "active": false,
    "nameservers": ["ns1.aziondns.net", "ns2.aziondns.com", "ns3.aziondns.org"],
    "product_version": "2.0"
  }
}
```

A `PATCH` changes only the fields you send. To turn the zone back on, send `{"active":true}`. A request that sends `domain` is refused with `19036` `Domain Cannot Be Modified`.

DNSSEC has its own endpoint. To turn it on, refer to [Turn on DNSSEC for a zone](/en/documentation/guides/application-security/dns/activate-dnssec/).

---

## Delete a zone

Deleting a zone removes it with its records and settings, and it cannot be reversed. To stop answers for the zone while you keep its records, turn **Active** off instead.

**Console**

To delete the zone in Azion Console:

1. **Open the Edge DNS page**

   Access [Azion Console](https://console.azion.com/) > **Edge DNS**.

2. **Select Delete on the zone's row**

   On the **Zones** page, open the actions of the zone's row and select **Delete**. The zone's edit page has no delete control.

3. **Type the zone name**

   In the **Delete zone** dialog, type the zone's name in the box.

4. **Select Delete**

The Console shows `Your Edge DNS has been deleted`, and the zone leaves the **Zones** list.

**CLI**

To delete the zone with the Azion CLI, replace `<zone-id>` with the ID of your zone:

```bash
azion delete dns-zone --zone-id <zone-id>
```

The command confirms the delete:

```text
DNS zone 1236 was successfully deleted
```

The zone and its records are deleted. Afterward, the zone no longer appears on the **Zones** page in Azion Console.

**API**

To delete the zone with the Azion API, send a `DELETE` request to the zone. Replace `<zone-id>` with the `id` of your zone:

```bash
curl -X DELETE https://api.azion.com/v4/workspace/dns/zones/<zone-id> \
  -H "Authorization: Token [TOKEN VALUE]"
```

The API answers `200`:

```json
{"state":"executed"}
```

The zone and its records are deleted. Afterward, the zone no longer appears on the **Zones** page in Azion Console, and a `GET` on its ID returns `404` with `10004` `Not Found`.

---

## Next steps

- [Add, edit, or delete a record](/en/documentation/guides/application-security/dns/add-records.md): Add the records the zone answers for.
- [Migrate nameservers to Azion](/en/documentation/guides/platform/migration/migrate-ns-to-azion.md): Delegate your domain to Edge DNS at the registrar.
- [Turn on DNSSEC for a zone](/en/documentation/guides/application-security/dns/activate-dnssec.md): Sign the zone and give the DS record to your registrar.
- [Zones and records](/en/documentation/platform/edge-dns/zones-and-records.md#zone-fields): Every zone field, its bounds, and its default.
