DNS Zone

Last Edited




Definition of Zone (DNS) in Network Encyclopedia.

What is DNS Zone?

DNS Zone also called a zone of authority, is a subset of the Domain Name System (DNS) namespace that is managed by a name server. This administrative unit can consist of a single domain, or it can be a domain combined with a number of subdomains. The concepts of a zone and a DNS domain are related: each zone is anchored in a specific domain known as the zone’s root domain.

DNS Zone
DNS Zone

How it works

The name server must have a zone file, which contains the mappings between IP addresses and hostnames for the zone. A name server can manage one or more zones, depending on how it is configured. For example, a name server might have one zone for the domain microsoft.com and another zone for the domain adventure.expedia.com. Depending on how the zone file is configured, a name server might be responsible for

  • A single domain and all of its subdomains (if any). In this case, the particular name server is said to be authoritative over its entire root domain.
  • A single domain and a portion of the tree of subdomains beneath it. In this case, other name servers are authoritative over the remaining portion of the tree of subdomains beneath the root domain. You might want to divide a domain into several zones managed by several name servers in order to assign the management of each zone to a different group or to make zone transfers more efficient.

Typically, at least two name servers are responsible for a given zone – a primary name server, which manages the actual zone file, and one or more secondary name servers for redundancy. The primary name server manages a standard primary zone, which is represented by a text file called a zone file. (You can modify this file by using a text editor such as Notepad or by using the Microsoft Windows Server administrative tool called DNS Manager.) Each secondary name server manages a standard secondary zone, which is represented by a read-only zone file that you obtain by copying the primary zone file from the primary name server via a process called zone transfer.

DNS Zone and Domains
Zone and Domains in DNS

DNS Zone examples in video

What are DNS ZONES ?

A DNS zone is any distinct, contiguous portion of the domain name space in the Domain Name System (DNS) for which administrative responsibility has been delegated to a single manager. The domain name space of the Internet is organized into a hierarchical layout of subdomains below the DNS root domain.

Most top-level domain name registry operators offer their name spaces to the public or to entities with mandated geographic or otherwise scoped purpose for registration of second-level domains. Similarly an organization in charge of a lower level domain may operate its name space similarly and subdivide its space.


In Microsoft Windows server-based networks, a DNS zone can take yet a third form, called an Active Directory integrated zone. In this type of zone, the zone information is stored and integrated into Active Directory of Windows Server for security purposes and is replicated by using the standard directory replication method used by Windows Server domain controllers. DNS in Windows Server supports dynamic update to ease the administrative burden of manually maintaining zone files.

See also: