Nine providers
Cloudflare, deSEC, Hetzner DNS, ClouDNS, Bunny DNS, Azure DNS, Amazon Route 53, DigitalOcean DNS and Gcore.
Your own DNS
Keep your zones where they are. Connect your own Cloudflare, deSEC, Hetzner DNS, ClouDNS, Bunny DNS, Azure DNS, Amazon Route 53, DigitalOcean DNS or Gcore account, and the records your sites need are written to it. We test the key before we save it.
A connection to the DNS account where your zones already live. Paste a key into Integrations and we test that it can read your zones, read their records and edit a record before anything is saved.
Your zones and your provider contract stay exactly where they are. The dashboard works on the account you connected, rather than asking you to move a domain's DNS to us.
Nine providers, all tested the same way.
Cloudflare, deSEC, Hetzner DNS, ClouDNS, Bunny DNS, Azure DNS, Amazon Route 53, DigitalOcean DNS and Gcore.
Zone read, record read and record edit are each checked before the key is saved, and you see which passed.
Connecting does not move your zones. They stay on your own account with your provider.
A key that passes is kept encrypted in our secrets vault, never in a database column or a log line.
Disconnecting removes the stored key. Your zones and records remain with your provider.
Each guide shows where to create the key on the provider's side, what it needs, and how to connect it in the dashboard.
Three steps, and your zones never leave your account.
Create an API token in your DNS account with access to the zones you want to use. Each provider's guide shows how.
Paste it in. Zone read, record read and record edit are tested before it is saved.
Once connected, the records your sites need are written to your own zones on that account.
Using your own DNS account is not an add-on.
We charge nothing for the connection. Your DNS provider bills you directly, on your own account, if it charges at all. Your Zinn Digital® hosting plan is billed as normal.
Query, zone and feature prices are your provider's, on your account. We never add to them.
DNS is what every visit to a domain depends on, and plenty of teams have good reasons to keep it with a provider they chose. Driving that account from the dashboard means you do not have to move it to host with us.
Record edit is tested before saving because DNS failures are quiet: a key that can read but not write looks fine until the first change silently does not happen.
Cloudflare, deSEC, Hetzner DNS, ClouDNS, Bunny DNS, Azure DNS, Amazon Route 53, DigitalOcean DNS and Gcore, each on your own account.
Zone read, record read and record edit. We test all three before saving and show you the result.
No. The key works on the zones already in your account, and they stay with your provider.
Your DNS provider, directly, if it charges. The connection costs nothing from us, and your hosting plan is billed as normal.
Only after it passes the tests, and then encrypted in our secrets vault. Disconnecting deletes it.
Step-by-step guides from our knowledge base, written for exactly this.
Send your clients' notifications from your own domain, on your own mail account: which provider to choose, the SPF, DKIM and return-path records they all need, why we insist a test message actually arrives, and what happens when a provider breaks.
Read the guide →Pools, bring-your-own accounts, and why footprint separation needs more than one account.
Read the guide →Keep it where it is registered and point it here — the two ways, and which to choose.
Read the guide →Create an account, open Integrations and paste in a token from your DNS provider. Zone read, record read and record edit are tested before it is saved.
Get started