Authentication
Send an API key as a bearer token. The key must carry the domains.dns.manage permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/domains/{domainId}/dns/records \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "name": <string>, "type": <DnsRecordType>, "value": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Adds a record to the domain's hosted zone. Requires `domains.dns.manage`. On the Footprint-Free line an A/AAAA record (or a `CNAME` to an IP literal, which resolves to one) is refused with a 422 — those are platform-managed. **Adding an apex `MX` is not additive** (issue #622). MX preference is lowest-number-wins, so a new record at or below the best existing preference takes delivery away from the host the customer's mail reaches today, without removing its record. That is refused `409 MAIL_CHANGE_REFUSED` unless `confirm_mail_change=true`; a strictly higher preference number is an ordinary backup MX and is allowed, as is the first `MX` on a domain that has none.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
domainId (path) | Uuid | Yes | The domain's id. |
confirm_mail_change (query) | boolean | No | Set `true` to proceed with a record change that would move or remove this domain's inbound email (issue #622). Without it, a write that stops mail reaching a host it reaches tod… |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
name | string | Yes | The record name — `@`/empty for the apex, or a relative/absolute host. |
type | DnsRecordType | Yes | A DNS resource-record type the shared editor supports (docs/31 §5.2). |
value | string | Yes | — |
ttl | integer | No | — |
priority | object | No | — |
proxied | object | No | Serve this record through the provider's HTTP proxy — Cloudflare's orange cloud. **`A` and `AAAA` only**; sending it on any other type is a `422` rather than a silent drop, beca… |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | string | Yes | The provider-assigned record id. |
name | string | Yes | The record name — `@` for the apex, or a relative/absolute host. |
type | DnsRecordType | Yes | A DNS resource-record type the shared editor supports (docs/31 §5.2). |
value | string | Yes | The record value (target/content). |
ttl | integer | Yes | Time-to-live in seconds. |
priority | object | No | Priority for MX/SRV records; null otherwise. |
proxied | object | No | Whether this record is served through the provider's HTTP proxy — Cloudflare's **orange cloud**. Applies to `A` and `AAAA`; providers without a proxy ignore it. ⛔⛔ **Three state… |
owner | DnsRecordOwner | Yes | Who may change this record. `platform` means the platform created it and converges it — the A/AAAA record at the apex or `www` that points the domain at the hosting we run for i… |
drift | DnsRecordDrift | No | What the last reconcile found about a **platform-owned** record at the provider, or `null` when the provider agrees with us (the overwhelmingly common case). `changed` — a recor… |
Errors this endpoint can return
401 · 403 · 404 · 409 · 422 · 429 · 502 · 503