Skip to content
Back to skills

Azure Dns

ASecurity

Expert coverage of Azure DNS: public and private zones, alias records, DNSSEC, Azure DNS Private Resolver (inbound/outbound endpoints, forwarding rulesets), Traffic Manager DNS routing, Azure Firewall DNS proxy, and Terraform/CLI management. Use for \"Azure DNS\", \"private zone\", \"Private Resolver\", \"alias record\", \"Azure DNSSEC\", \"DNS forwarding ruleset\", \"Traffic Manager\", \"Azure Firewall DNS\". Do NOT use for cross-vendor comparison, platform selection, or category-wide archit...

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
devopsgobashsqlazureterraformtestingdatabasesecurityperformance

Works with

  • cli

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill azure-dns --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Azure Dns?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Azure Dns
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-azure-dns/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-azure-dns)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: azure-dns
description: "Expert coverage of Azure DNS: public and private zones, alias records, DNSSEC, Azure DNS Private Resolver (inbound/outbound endpoints, forwarding rulesets), Traffic Manager DNS routing, Azure Firewall DNS proxy, and Terraform/CLI management. Use for \"Azure DNS\", \"private zone\", \"Private Resolver\", \"alias record\", \"Azure DNSSEC\", \"DNS forwarding ruleset\", \"Traffic Manager\", \"Azure Firewall DNS\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- use the `dns` skill. Do NOT use for general Azure account/resource management beyond DNS -- that's the `azure` skill (in the `cloud-platforms` plugin)."
license: MIT
---

# Azure DNS

This skill covers Azure DNS -- Microsoft's managed DNS platform spanning public authoritative DNS, private DNS zones, hybrid resolution, and DNS-based traffic routing. Areas of expertise include:

- Public zones on Azure's anycast nameserver infrastructure (ns1-0x.azure-dns.com)
- Private zones for VNet-internal resolution with auto-registration
- Alias records for zone apex support with auto-updating Azure resource targets
- DNSSEC for public zones (auto-managed key rotation)
- Azure DNS Private Resolver (inbound/outbound endpoints, DNS forwarding rulesets)
- Hybrid DNS flows (on-prem to Azure, Azure to on-prem)
- Traffic Manager (DNS-based routing: priority, weighted, performance, geographic)
- Azure Firewall DNS proxy for FQDN-based network rules
- Management via Azure Portal, Azure CLI, Terraform, ARM/Bicep templates

## How to Approach Tasks

1. **Classify** the request:
   - **Public DNS** -- Zone hosting, record management, DNSSEC, alias records
   - **Private DNS** -- VNet-linked zones, auto-registration, private endpoint resolution
   - **Hybrid DNS** -- Private Resolver (inbound/outbound), forwarding rulesets
   - **Traffic routing** -- Traffic Manager profiles, routing methods, health checks
   - **Security** -- DNSSEC, Azure Firewall DNS proxy, FQDN-based rules
   - **Architecture** -- Load `references/architecture.md` for deployment patterns

2. **Identify scenario** -- Public-facing DNS, private endpoint resolution, hybrid on-prem integration, multi-region traffic routing, or firewall DNS logging.

3. **Identify management method** -- Portal, Azure CLI (`az network dns`), Terraform (`azurerm_dns_zone`), or ARM/Bicep.

4. **Recommend** -- Provide specific configuration with Azure CLI commands and/or Terraform resources.

## Public Zones

Azure DNS hosts public authoritative zones on globally distributed anycast nameserver infrastructure:

- Four NS records per zone (ns1-0x through ns4-0x across azure-dns.com/.net/.org/.info)
- Supported record types: A, AAAA, CNAME, MX, NS, PTR, SOA, SRV, TXT, CAA
- Delegation: update NS records at domain registrar to point to Azure nameservers
- 100% SLA for valid DNS queries

```bash
# Create public zone
az network dns zone create -g MyRG -n example.com

# Add A record
az network dns record-set a add-record -g MyRG -z example.com -n www -a 10.1.1.1

# Add MX record
az network dns record-set mx add-record -g MyRG -z example.com -n @ \
    -e mail.example.com -p 10
```

### DNSSEC (Public Zones)

```bash
# Enable DNSSEC signing
az network dns dnssec-config create -g MyRG -z example.com

# Get DS records for parent registration
az network dns dnssec-config show -g MyRG -z example.com
```

- Supported algorithms: ECDSAP256SHA256, ECDSAP384SHA384, ED25519
- Azure manages key rollovers automatically
- DS records must be published at parent registrar
- DNSSEC is NOT supported on private zones

### Alias Records

Azure-specific DNS records pointing to Azure resources:

- Supported targets: Azure Public IP, Traffic Manager, CDN, Front Door
- **Zone apex support**: alias records can exist at the zone root (unlike CNAME)
- **Auto-updating**: target IP changes propagate automatically
- Supported for A, AAAA, CNAME record types

```bash
# Alias to Azure Public IP
az network dns record-set a create -g MyRG -z example.com -n @ \
    --target-resource "/subscriptions/.../providers/Microsoft.Network/publicIPAddresses/myPIP"
```

Terraform:
```hcl
resource "azurerm_dns_a_record" "apex" {
  name                = "@"
  zone_name           = azurerm_dns_zone.example.name
  resource_group_name = azurerm_resource_group.main.name
  ttl                 = 300
  target_resource_id  = azurerm_public_ip.main.id
}
```

## Private Zones

DNS resolution within VNets -- not publicly resolvable:

```bash
# Create private zone
az network private-dns zone create -g MyRG -n internal.example.com

# Link to VNet with auto-registration
az network private-dns link vnet create -g MyRG -z internal.example.com \
    -n mylink --virtual-network myVNet --registration-enabled true
```

- **VNet links**: associate private zone with VNets
- **Auto-registration**: VMs in linked VNet get DNS records automatically (VM-name.zone)
- Same record types as public zones (no DNSSEC)
- Use case: private endpoint resolution, internal service names

### Private Endpoint DNS

Private endpoints require DNS resolution to return the private IP:

```
# Standard resolution: mydb.database.windows.net → public IP
# With private endpoint: mydb.database.windows.net
#   → mydb.privatelink.database.windows.net (CNAME)
#   → 10.0.1.5 (private IP from private DNS zone)
```

Required private DNS zone: `privatelink.database.windows.net` (varies by service).

## Azure DNS Private Resolver

Fully managed DNS proxy for hybrid resolution:

### Architecture

```
┌──────────────────────────────────────────────────┐
│                    Azure VNet                     │
│                                                  │
│  ┌─────────────────┐    ┌──────────────────┐     │
│  │ Inbound Endpoint│    │ Outbound Endpoint │    │
│  │ (10.0.1.4)      │    │ (10.0.2.4)       │    │
│  │                 │    │                   │    │
│  │ On-prem DNS ───►│    │ ──► On-prem DNS   │    │
│  │ forwards here   │    │    (via ruleset)  │    │
│  └─────────────────┘    └──────────────────┘     │
│                                                  │
│  ┌────────────────────────────────────────┐      │
│  │ DNS Forwarding Ruleset                │      │
│  │ corp.internal → 10.10.0.53, 10.10.0.54│      │
│  │ ad.contoso.com → 10.10.0.53           │      │
│  └────────────────────────────────────────┘      │
└──────────────────────────────────────────────────┘
```

### Inbound Endpoint

- Assigns private IP within your VNet
- On-premises DNS conditionally forwards to this IP
- Resolves using Azure Private DNS zones linked to the VNet
- Use case: on-prem resolving Azure private endpoints (e.g., SQL Private Link)

### Outbound Endpoint

- Used for conditional forwarding from Azure to on-premises
- Associated with DNS Forwarding Ruleset
- Use case: Azure VMs resolving on-premises Active Directory domains

### DNS Forwarding Ruleset

```bash
# Create ruleset
az dns-resolver forwarding-ruleset create -g MyRG -n myRuleset \
    --outbound-endpoints "[{id:'/subscriptions/.../outboundEndpoints/outbound'}]"

# Add forwarding rule
az dns-resolver forwarding-rule create -g MyRG --ruleset-name myRuleset \
    -n corp-internal --domain-name "corp.internal." \
    --target-dns-servers "[{ip-address:10.10.0.53,port:53},{ip-address:10.10.0.54,port:53}]"

# Link ruleset to VNet
az dns-resolver vnet-link create -g MyRG --ruleset-name myRuleset \
    -n mylink --id "/subscriptions/.../virtualNetworks/myVNet"
```

Up to 1,000 forwarding rules per ruleset. Ruleset linkable to multiple VNets.

### Hybrid DNS Flows

**On-prem to Azure (private endpoint resolution):**
```
On-prem DNS ──► conditional forward *.privatelink.database.windows.net
    ──► Inbound Endpoint (10.0.1.4)
    ──► Azure Private DNS zone
    ──► Returns private endpoint IP (10.0.1.5)
```

**Azure to on-prem (AD/corporate DNS):**
```
Azure VM resolves corp.internal
    ──► 168.63.129.16 (Azure DNS wire server)
    ──► Outbound Endpoint
    ──► Forwarding Ruleset matches corp.internal
    ──► Forwards to 10.10.0.53 (on-prem DNS)
    ──► Returns on-prem record
```

## Traffic Manager

DNS-based global traffic routing:

| Routing Method | Use Case | Key Config |
|---|---|---|
| Priority | Active/passive failover | Priority value per endpoint |
| Weighted | A/B testing, canary | Weight 1-1000 per endpoint |
| Performance | Lowest latency | Azure region per endpoint |
| Geographic | Country/region-based | Geographic mapping |
| Subnet | Client IP-based | CIDR ranges |
| Multivalue | Client-side load balancing | Up to 8 healthy endpoints |

```bash
# Create profile
az network traffic-manager profile create -g MyRG -n myProfile \
    --routing-method Performance --unique-dns-name myapp

# Add endpoint
az network traffic-manager endpoint create -g MyRG --profile-name myProfile \
    -n eastus --type azureEndpoints --target-resource-id <public-ip-id> \
    --endpoint-status enabled
```

Health probes: HTTP/HTTPS/TCP checks per endpoint. Nesting: profiles can be nested for complex routing.

## Azure Firewall DNS Proxy

```bash
# Enable DNS proxy on Azure Firewall
az network firewall update -g MyRG -n myFW --enable-dns-proxy true \
    --dns-servers 10.0.0.53 168.63.129.16
```

- VNet DNS servers point to Azure Firewall private IP
- Firewall forwards queries to configured DNS servers
- Enables DNS logging through Azure Firewall diagnostic logs
- **Required** for FQDN-based network rules and application rules
- DNS proxy chain: Azure Firewall -> custom DNS -> Azure DNS

## Common Pitfalls

1. **Private zone not linked to VNet** -- Private DNS zones must be explicitly linked to each VNet. VNet peering does NOT automatically share DNS. VMs in unlinked VNets cannot resolve private zone records.
2. **Auto-registration conflict** -- A VNet can only have auto-registration enabled for one private DNS zone. Attempting to link with auto-registration to a second zone fails.
3. **Private Resolver subnet requirements** -- Inbound and outbound endpoints require dedicated subnets (minimum /28). These subnets cannot contain other resources.
4. **DNSSEC DS record at registrar** -- After enabling DNSSEC on a public zone, the DS record must be manually published at the domain registrar. Without it, DNSSEC validation fails for resolvers.
5. **Traffic Manager TTL** -- Traffic Manager DNS TTL (default 60s) affects failover speed. Lower TTL = faster failover but more DNS queries. Do not set below 10s.
6. **Azure Firewall DNS proxy required for FQDN rules** -- FQDN-based network rules in Azure Firewall only work when DNS proxy is enabled. Without it, FQDN resolution fails silently.
7. **Private endpoint DNS zone naming** -- Each Azure service has a specific private DNS zone name (e.g., `privatelink.database.windows.net` for SQL, `privatelink.blob.core.windows.net` for Blob). Using the wrong zone name breaks resolution.

## Reference Files

- `references/architecture.md` -- Public/private zones, Private Resolver, DNSSEC, alias records

Files in this skill

  • SKILL.md11.5 KB
  • references/architecture.md13.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…