domains
GET /v1/domains/{domainId}/dns/records
List a page of a domain's DNS records.
Authentication
Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/domains/{domainId}/dns/records \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
The resource records in the domain's hosted authoritative zone. Requires `sites.view`, RLS-scoped. **Footprint-Free (PBN) line:** the A/AAAA records publish the shared fleet IP and are hidden entirely from this line (they are platform-managed) — the returned set never contains them (register #93). **Paginated (issue #466).** Keyset cursor over `(name, type, value, id)`, default page size 50, hard maximum 200. Filtering by product line happens **before** pagination, so a hidden record can never surface on a later page. A client must follow `page.next_cursor` until `page.has_more` is false; reading only the first page reads only the first page. **Two different 404s, and a client MUST branch on the `code` rather than the status.** `NOT_FOUND` is the ordinary miss — no such domain, or not in your scope. `DNS_NOT_HOSTED` means the domain exists and is yours, but its nameservers point at another DNS provider, so there is no zone here to read. The second is **permanent until the customer re-delegates** and retrying can never succeed; on a Footprint-Free estate, where most names are registered elsewhere and merely pointed at us, it is the normal answer for most domains rather than an edge case. Both carry the identical message, deliberately, so that a caller who may not see the domain cannot tell the two apart by wording.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
domainId (path) | Uuid | Yes | The domain's id. |
cursor (query) | string | No | Opaque cursor from a previous page's `page.next_cursor`. |
limit (query) | integer | No | Maximum items to return (page size). |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
data | DnsRecord[] | Yes | — |
page | PageMeta | Yes | — |
Errors this endpoint can return
401 · 403 · 404 · 429 · 502 · 503