# Edge DNS quickstart

This guide instructs you through hosting your first zone on [Edge DNS](/en/documentation/platform/edge-dns/), before anything public changes. By the end you will have:

- A zone for your domain, served by Azion's three nameservers.
- An A record that maps `www` to `192.0.2.1`.
- An authoritative answer for `www` from `ns1.aziondns.net`.

Two objects and one registrar setting make Edge DNS answer for a domain. The **zone** holds one domain, such as `example.com`. A **record** belongs to a zone and maps one name in it to a value: here, `www` to an IPv4 address. Azion's three nameservers answer queries for every record of the zone. Resolvers on the internet ask them only after the domain's registrar delegates the domain to them. This guide stops before the delegation, so the domain keeps resolving as before until you change the registrar.

---

Select the interface you will use. The prerequisites, the zone, and the record follow that choice.

## Prerequisites

- A domain you control, and access to its registrar. You need the registrar only for the delegation at the end of this guide.
- The **Edit Edge DNS** permission. It grants access to create, edit, and remove zones, and it requires **View Edge DNS**. Refer to [Teams permissions](/en/documentation/fundamentals/teams-permissions/).
- `dig` on your machine, to query the zone at Azion's nameservers. To install it, refer to [Query a zone with dig](/en/documentation/guides/application-security/dns/run-the-dig-command/).

**Console**

- Access to Azion Console. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**CLI**

- The [Azion CLI](/en/documentation/devtools/cli/) installed and authorized.

**API**

- A [personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/) and `curl`.

---

## Create a zone

The zone holds your domain and every record Edge DNS answers for it. Replace `example.com` with your domain in every step.

**Console**

To create the zone in Azion Console:

1. **Open the Edge DNS page**

   Access [Azion Console](https://console.azion.com/) > **Edge DNS**.

2. **Select + Zone**

3. **Name the zone**

   In the **General** section, enter a **Name**, such as `example-zone`. The name identifies the zone in lists. It is not the domain.

4. **Enter the domain**

   In the **Domain Name** section, enter your root domain in **Domain Name**, such as `example.com`.

5. **Keep Active turned on**

   In the **Status** section, keep **Active** turned on.

6. **Select Create**

The Console opens the zone's **Records** tab. It confirms the zone with `Your DNS zone has been created. To complete the setup, ensure the Azion nameservers are configured in your domain provider.` The end of this guide covers the nameservers.

**CLI**

To create the zone with the Azion CLI, run:

```bash
azion create dns-zone --name example-zone --domain example.com --active=true
```

The command prints the ID of the zone:

```text
Created DNS zone with ID 1235
```

The zone exists and is active. Record the ID: the record you add needs it.

**API**

To create the zone with the Azion API, send a `POST` request to the zones endpoint. Replace `[TOKEN VALUE]` with your personal token:

```bash
curl -X POST https://api.azion.com/v4/workspace/dns/zones \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Content-Type: application/json" \
  -d '{"name":"example-zone","domain":"example.com","active":true}'
```

A `201` returns the zone:

```json
{
  "state": "executed",
  "data": {
    "id": 1234,
    "name": "example-zone",
    "domain": "example.com",
    "active": true,
    "nameservers": ["ns1.aziondns.net", "ns2.aziondns.com", "ns3.aziondns.org"],
    "product_version": "2.0"
  }
}
```

The `nameservers` array lists the three nameservers that answer for the zone. Record the `id`: the record you add needs it.

A zone's domain cannot change after creation, and no other zone in Azion can host the same domain. For every zone field and its rules, refer to [Zones and records](/en/documentation/platform/edge-dns/zones-and-records/#zone-fields).

---

## Add a record

An A record maps a name to an IPv4 address. This one answers `192.0.2.1` for `www.example.com`. A record name is relative to the zone, so you enter `www` and Edge DNS adds the domain.

**Console**

To add the record in Azion Console:

1. **Select + Record**

   On the zone's **Records** tab, select **+ Record**. The **Create Record** drawer opens.

2. **Enter the record name**

   In **Name**, enter `www`. The Console shows your domain after the field and adds it for you, so never type the domain.

3. **Keep the A record type**

   Keep **Record Type** set to *A - IPv4 Address*.

4. **Keep the TTL**

   Keep **TTL (seconds)** at `3600`.

5. **Enter the value**

   In **Value**, enter `192.0.2.1`.

6. **Select Save**

The Console shows `Edge DNS Record has been created`, and the record appears in the **Records** table.

**CLI**

To add the record with the Azion CLI, replace `<zone-id>` with the ID of the zone you created:

```bash
azion create dns-record --zone-id <zone-id> --name www --type A --rdata 192.0.2.1 --ttl 3600
```

The command prints the ID of the record:

```text
Created DNS record with ID 100228
```

The zone holds the record. Never include the domain in `--name`: Edge DNS adds it.

**API**

To add the record with the Azion API, send a `POST` request to the zone's records endpoint. Replace `<zone-id>` with the `id` of the zone you created:

```bash
curl -X POST https://api.azion.com/v4/workspace/dns/zones/<zone-id>/records \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Content-Type: application/json" \
  -d '{"name":"www","type":"A","rdata":["192.0.2.1"],"ttl":3600}'
```

A `201` returns the record, with defaults for the fields the request leaves out:

```json
{
  "state": "executed",
  "data": {
    "id": 100172,
    "description": "",
    "name": "www",
    "ttl": 3600,
    "type": "A",
    "rdata": ["192.0.2.1"],
    "policy": "simple",
    "weight": 255
  }
}
```

The zone holds the record. Never include the domain in `name`: Edge DNS adds it.

For every record field, refer to [Zones and records](/en/documentation/platform/edge-dns/zones-and-records/#record-fields).

---

## Query the zone at Azion's nameservers

Ask Azion's nameserver directly, without your resolver's cache, to confirm that it answers for the record. This check needs no change at the registrar.

> **Caution**
>
> Query a name only after you save its record. A name queried before its record exists is answered `NXDOMAIN` for up to one hour, the SOA minimum, even after you add the record.

To query `ns1.aziondns.net` for the record, replace `example.com` with your domain:

```bash
dig +short @ns1.aziondns.net www.example.com A
```

The nameserver returns the value of the record:

```text
192.0.2.1
```

The first record of a zone can take a few minutes to be answered. If the command prints nothing, wait a few minutes and run it again. If it still prints nothing, refer to [A new record returns NXDOMAIN](/en/documentation/platform/edge-dns/troubleshooting/#a-new-record-returns-nxdomain).

To read how the nameserver answered, run the query without `+short`:

```bash
dig @ns1.aziondns.net www.example.com A
```

The header of the output carries the status and the flags:

```text
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 17320
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
…
```

`status: NOERROR` with `ANSWER: 1` means the nameserver answered with the record. The `aa` flag marks an authoritative answer, one that comes from a nameserver that hosts the zone.

Azion's nameservers now answer for your zone. Resolvers on the internet do not ask them yet: until the registrar delegates the domain, a public resolver such as `8.8.8.8` finds no delegation to Azion.

To make Edge DNS answer for the domain, delegate it at your registrar to all three Edge DNS nameservers:

- `ns1.aziondns.net`
- `ns2.aziondns.com`
- `ns3.aziondns.org`

In Azion Console, **Copy Nameserver Values** on the **Zones** page copies the three names, joined by semicolons. The API returns them in the zone's `nameservers` array, and `azion describe dns-zone --zone-id <zone-id>` prints them under `Nameservers:`. Before you delegate, add the records your domain needs, with your own addresses in place of `192.0.2.1`. For the full migration, refer to [Migrate nameservers to Azion](/en/documentation/guides/platform/migration/migrate-ns-to-azion/).

---

## Next steps

- [Migrate nameservers to Azion](/en/documentation/guides/platform/migration/migrate-ns-to-azion.md): Delegate your domain to Edge DNS at the registrar.
- [Zones and records](/en/documentation/platform/edge-dns/zones-and-records.md): Every zone and record field, the nameservers, and the API errors.
- [Record types](/en/documentation/platform/edge-dns/record-types.md): The value format and rules of each of the 11 record types.
- [Point an apex domain with ANAME](/en/documentation/guides/application-security/dns/access-root-domain.md): Answer for the root domain with an Azion workload.
