# Glossary

This glossary defines the terms that the [Edge DNS](/en/documentation/platform/edge-dns/) documentation uses for zones, records, and DNSSEC, with their Azion Console labels and Azion API fields.

| Term                 | Definition                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| active               | The state of a zone whose names Edge DNS answers, set by the **Active** switch, the `active` field, and the `--active=true` or `--active=false` CLI flag. The **Zones** list shows each zone as *Active* or *Inactive*, and an inactive zone keeps its records while the nameservers answer its names with `REFUSED`. Deactivation can take a few minutes to reach every nameserver, and [Zones and records](/en/documentation/platform/edge-dns/zones-and-records/#zone-fields) describes the field.                                                                                                  |
| ANAME                | A record type that points a name, the apex `@` included, at one or more targets under `azioncdn.net`, `azionedge.net`, or `azionedge.com`. The Console lists it as *ANAME - Maps a name to another name*, and its `ttl` must be `20`, which the Console pre-fills. A CNAME is refused at `@`, so an ANAME points the apex at an Azion target, as [Record types](/en/documentation/platform/edge-dns/record-types/#aname) describes.                                                                                                                                                                    |
| apex                 | The zone's domain itself, such as `example.com`, which a record names with `@` in the **Name** field and in `name`. A CNAME record is refused at the apex with `19005`, and an ANAME record takes its place for an Azion target. [Point an apex domain with ANAME](/en/documentation/guides/application-security/dns/access-root-domain/) gives the steps.                                                                                                                                                                                                                                             |
| DNSSEC status        | The state of a zone's [DNSSEC](https://www.azion.com/en/learning/dns/what-is-dnssec/) signing, returned in the API's `status` field as `unconfigured`, `waiting`, or `ready`, and printed by `azion describe dnssec`. `ready` means that Azion signed the zone and holds its DS values, not that your registrar has them. The status stays `ready` after DNSSEC is turned off, the Console never shows it, and [DNSSEC](/en/documentation/platform/edge-dns/dnssec/#status) describes each value.                                                                                                      |
| DS record            | The delegation signer record that your registrar publishes for a signed zone, built from **Key Tag**, **Algorithm**, **Digest Type**, and **Digest**, which is a hash of the key-signing key. The Console shows the four values in the **DNSSEC** section of **Main Settings**, the API returns them in `delegation_signer`, and [DNSSEC](/en/documentation/platform/edge-dns/dnssec/#ds-record) describes the record. A *DS - Delegation Signer* record inside a zone is different: it delegates a child zone, as [Record types](/en/documentation/platform/edge-dns/record-types/#ds) describes.     |
| Edge DNS nameservers | The three nameservers that answer [DNS](https://www.azion.com/en/learning/dns/what-is-dns/) queries for every zone: `ns1.aziondns.net`, `ns2.aziondns.com`, and `ns3.aziondns.org`. They are read-only, and the API returns them in `nameservers` while the Console lists them under **Configure your Nameserver**. A domain is served by Edge DNS once its registrar delegates it to all three, as [Zones and records](/en/documentation/platform/edge-dns/zones-and-records/#nameservers-and-soa) describes.                                                                                         |
| policy               | The rule that decides how a record answers, set in the **Policy Type** field and in `policy`. The options are *Simple* (`simple`), the default, and *Weighted* (`weighted`). [How Edge DNS works](/en/documentation/platform/edge-dns/how-it-works/#record-policies) describes both.                                                                                                                                                                                                                                                                                                                   |
| record               | One name, type, and set of values inside a zone, which Edge DNS returns as the answer to a query for that name and type. The Console adds it in the **Create Record** drawer of the zone's **Records** tab, and the API creates it under `/v4/workspace/dns/zones/<zone-id>/records`. A field the request leaves out takes its default, such as a `ttl` of `3600`, as [Zones and records](/en/documentation/platform/edge-dns/zones-and-records/#record-fields) describes.                                                                                                                             |
| record name          | The **Name** of a record and its `name` field, written relative to the zone: `www` answers for `www.example.com`, and `@` answers for the apex. A name typed with the domain is served with the domain twice, such as `www.example.com.example.com`, which is why the Console shows the domain as a suffix. A name holds up to 255 characters, and [Zones and records](/en/documentation/platform/edge-dns/zones-and-records/#record-fields) describes the field.                                                                                                                                      |
| simple policy        | The default policy, *Simple* in **Policy Type** and `simple` in `policy`, which answers a query with every value of the record. A name and type hold one simple record, and a second one is refused with `19004`, so several answers go in one record's value. [How Edge DNS works](/en/documentation/platform/edge-dns/how-it-works/#record-policies) compares it with the weighted policy.                                                                                                                                                                                                           |
| value                | The answers of a record, one per line in the Console **Value** field, the `rdata` array in the API, and the `--rdata` flag in the CLI. Most record types take up to 10 values, and the format of each value depends on the type. [Record types](/en/documentation/platform/edge-dns/record-types/) gives the format and the bound of each type.                                                                                                                                                                                                                                                        |
| weight               | The number from 0 to 255 that sets a weighted record's share of the answers, set in the **Weight** field and in `weight`. The share is the record's weight over the sum of the weights of the records that share its name and type, and a weight of `0` keeps the record but never answers it. The API default is `255` and the Console pre-fills `100`, as [Zones and records](/en/documentation/platform/edge-dns/zones-and-records/#record-fields) describes.                                                                                                                                       |
| weighted policy      | The policy, *Weighted* in **Policy Type** and `weighted` in `policy`, that lets several records share one name and type, each with its own weight. It is accepted on A, AAAA, CNAME, ANAME, and MX records, and each answer carries one value, which a client keeps for the record's [TTL](https://www.azion.com/en/learning/dns/how-dns-cache-works/). [How Edge DNS works](/en/documentation/platform/edge-dns/how-it-works/#record-policies) describes the selection, and [Weight records to balance traffic](/en/documentation/guides/application-security/dns/load-balance-dns/) gives the steps. |
| wildcard record      | A record whose name starts with a `*` label, such as `*` or `*.apps`, that answers names the zone does not list. A `*` record at the root answers every unlisted name, even several labels deep, and an explicit name always wins over it. An asterisk inside a label, as in `a*b`, is a literal character, and [Record types](/en/documentation/platform/edge-dns/record-types/#wildcards) describes the matching.                                                                                                                                                                                    |
| zone                 | The Edge DNS object that hosts one domain and holds its records, created on the **Create Zone** page or with `POST /v4/workspace/dns/zones`. A zone carries a **Name** of 1 to 50 characters for your reference, and a **Domain Name** that is fixed at creation. To serve another domain, create another zone, as [Zones and records](/en/documentation/platform/edge-dns/zones-and-records/#zone-fields) describes.                                                                                                                                                                                  |
