DNS Record Generator
Build correctly formatted DNS records in zone file syntax, with the trailing dot rules, TXT string splitting and CNAME restrictions that cause most record errors.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
The trailing dot changes the meaning
In zone file syntax, a name ending in a dot is absolute and one without is relative to the current origin. Writing mail.example.com without the dot in a zone for example.com produces mail.example.com.example.com, which resolves to nothing and looks correct in the file. This single character causes more DNS errors than any other detail, and it applies to every field containing a name: the target of a CNAME, the exchange in an MX record, the nameserver in an NS record and the target of an SRV.
A CNAME cannot coexist with anything
The specification is explicit: if a name has a CNAME record, it may have no other records of any type at that name. That is why a CNAME cannot be placed at the apex of a zone, where the mandatory SOA and NS records already exist, and it is why providers invented ALIAS and ANAME records that behave like a CNAME at the apex while returning an address in the answer. Those records are not standard and their behaviour differs between providers.
TXT records have a 255 character string limit
A single character string within a TXT record cannot exceed 255 bytes, so a longer value such as a DKIM public key must be split into several quoted strings which the resolver concatenates. Most providers handle this automatically and some do not, and a DKIM key that was pasted as one long string is a common reason signature verification fails while the record appears present.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
When do I need a trailing dot?
On any fully qualified name in a zone file: CNAME targets, MX exchanges, NS names, SRV targets and PTR values. Without it the name is treated as relative to the zone origin and the origin is appended, producing a name that does not exist.
Why can I not put a CNAME at the apex?
Because a CNAME must be the only record at its name, and the apex necessarily has SOA and NS records. Providers offer ALIAS or ANAME records that resolve the target and return its address, which achieves the same effect without violating the specification.
What is the priority field in an MX record?
A preference value where lower is tried first. Equal values are load balanced. The numbers themselves are arbitrary, so 10 and 20 are conventional simply to leave room to insert a value between them later.
Why must long TXT records be split?
A character string in a TXT record is limited to 255 bytes. Longer values are expressed as several quoted strings which the resolver joins together. A DKIM key pasted as one long string is a common reason verification fails while the record looks present.
What does the underscore in an SRV name mean?
SRV records use an underscore prefixed service and protocol label, such as _sip._tcp.example.com, so they cannot collide with a hostname. The same convention is used by DKIM selectors, DMARC and ACME challenge records.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Choose a record type and fill in the fields to get correctly formatted zone file syntax.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.