DNS Zone File Validator
Validate a DNS zone file for syntax errors, missing trailing dots, CNAME conflicts, SOA field problems and the record combinations that resolvers handle inconsistently.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
A zone loads or it does not, with no partial credit
Authoritative nameservers reject a zone file with a syntax error outright rather than loading the valid portion, so a single missing bracket in a SOA record takes the entire domain offline at the next reload. BIND logs the failure and continues serving the previously loaded copy, which means the error can sit unnoticed until a restart hours or days later, at which point the domain stops resolving for reasons that appear unconnected to whatever was changed.
The conflicts a parser accepts and resolvers dislike
Syntax is not the whole problem. A CNAME alongside any other record at the same name is invalid, and while some servers load it anyway, resolvers behave inconsistently. An MX or NS record pointing at a CNAME is prohibited and causes intermittent mail delivery failure. Two SPF records at the same name is a permanent error that fails every check rather than one taking precedence. None of these are syntax errors, and all of them break something.
The serial is what makes changes propagate
Secondary nameservers compare the SOA serial to decide whether to transfer the zone, so a change with an unincremented serial is loaded on the primary and never reaches the secondaries. The domain then resolves differently depending on which nameserver a resolver happens to ask, which produces the most confusing class of DNS fault there is: intermittent, unreproducible, and correct on whichever server the person investigating checks first.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
What happens if a zone file has a syntax error?
The nameserver refuses to load the whole zone rather than loading the valid part. BIND continues serving the previously loaded copy and logs the failure, so the error frequently goes unnoticed until a restart, at which point the domain stops resolving.
Why must I increment the serial?
Secondary nameservers compare the SOA serial to decide whether to transfer the zone. Without an increment they keep the old copy, so the domain resolves differently depending on which nameserver is asked, which is the most confusing kind of DNS fault.
Can a CNAME have other records alongside it?
No. The specification requires a CNAME to be the only record at its name. Some servers load a zone that violates this and resolvers then behave inconsistently, which is worse than a clean failure because it works for some users.
Why can an MX record not point at a CNAME?
The specification prohibits it and mail servers reject it. The MX target must have its own A or AAAA record. This causes intermittent delivery failure that depends on the receiving server’s strictness, so it works for some senders and not others.
What should the SOA minimum field be?
Since RFC 2308 it is the negative caching TTL, controlling how long a resolver remembers a name does not exist, rather than a default TTL. A high value means a newly created record stays invisible to anyone who queried too early, so 300 to 3600 seconds is usually right.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste your zone file to check it for syntax and consistency problems.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.