Authentication
Send an API key as a bearer token. The key must carry the domains.dns.manage permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X PUT https://api.zinndigital.com/v1/domains/{domainId}/dns/records/{recordId} \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "name": <string>, "type": <DnsRecordType>, "value": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Replaces the record `recordId` in the domain's hosted zone. Requires `domains.dns.manage`. A record hidden from the caller's product line (an A/AAAA on the Footprint-Free line) is indistinguishable from an absent one — a 404 — so it cannot be probed by id (register #93). **Repointing a live apex `MX` is refused** `409 MAIL_CHANGE_REFUSED` unless `confirm_mail_change=true` (issue #622) — it silently stops the customer's email reaching the mailboxes it reaches today, which is data loss rather than a configuration change. So is moving the only apex `MX` onto a subdomain: the record survives, the domain's mail does not. A change that alters only TTL or preference is not refused, because mail still arrives at the same host.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
domainId (path) | Uuid | Yes | The domain's id. |
recordId (path) | string | Yes | The DNS record's provider id. |
confirm_mail_change (query) | boolean | No | Set `true` to proceed with a record change that would move or remove this domain's inbound email (issue #622). Without it, a write that stops mail reaching a host it reaches tod… |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
name | string | Yes | The record name — `@`/empty for the apex, or a relative/absolute host. |
type | DnsRecordType | Yes | A DNS resource-record type the shared editor supports (docs/31 §5.2). |
value | string | Yes | — |
ttl | integer | No | — |
priority | object | No | — |
proxied | object | No | Serve this record through the provider's HTTP proxy — Cloudflare's orange cloud. **`A` and `AAAA` only**; sending it on any other type is a `422` rather than a silent drop, beca… |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | string | Yes | The provider-assigned record id. |
name | string | Yes | The record name — `@` for the apex, or a relative/absolute host. |
type | DnsRecordType | Yes | A DNS resource-record type the shared editor supports (docs/31 §5.2). |
value | string | Yes | The record value (target/content). |
ttl | integer | Yes | Time-to-live in seconds. |
priority | object | No | Priority for MX/SRV records; null otherwise. |
proxied | object | No | Whether this record is served through the provider's HTTP proxy — Cloudflare's **orange cloud**. Applies to `A` and `AAAA`; providers without a proxy ignore it. ⛔⛔ **Three state… |
owner | DnsRecordOwner | Yes | Who may change this record. `platform` means the platform created it and converges it — the A/AAAA record at the apex or `www` that points the domain at the hosting we run for i… |
drift | DnsRecordDrift | No | What the last reconcile found about a **platform-owned** record at the provider, or `null` when the provider agrees with us (the overwhelmingly common case). `changed` — a recor… |
Errors this endpoint can return
401 · 403 · 404 · 409 · 422 · 429 · 502 · 503