Azure Public DNS Zone & Records
An Azure public DNS zone plus a map-driven set of record sets - A, AAAA, CNAME, TXT, MX, NS, CAA and SRV - with relative naming, verbatim TXT values, and apex footgun guards.
Compare DNS & Traffic Management across clouds →
Part of: Azure Production Landing Zone
Verification
Live-testedReally deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.
Conformance
- Static validation (fmt · validate · tflint)
- Security scan pending (Checkov)
- Plan test superseded by live test
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-06-30 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o azure-dns-zone-1.0.1.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/azure-dns-zone/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle azure-dns-zone-1.0.1.sigstore.json \
azure-dns-zone-1.0.1.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "85222e5469fef66f3b65a6d6a8459256dc8434d93686d7806318f15f163d24ac azure-dns-zone-1.0.1.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "dns_zone" {
source = "www.iac-bazaar.com/iac-bazaar/azure-dns-zone/azure"
version = "1.0.1"
}Free module — Terraform/OpenTofu downloads it with no token or setup. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.
This module is in the Free band, and a free account sees the contract of every Free module — no subscription needed.
Documentation
azure-dns-zone
Azure public DNS zone (azurerm_dns_zone) plus a clean, map-driven set
of record sets — A, AAAA, CNAME, TXT, MX, NS, CAA and SRV. Works with
Terraform and OpenTofu (>= 1.6), azurerm provider >= 4.0, < 5.0. The
module consumes an existing resource group (DNS zones are global, so there
is no location to set).
Each record type maps to its own azurerm resource via for_each, so addressing
is stable and editing one entry never churns the others. The fiddly Azure-isms
are handled or documented for you:
- Record names are relative to the zone — use
"@"(the default) for the apex or a label like"www"; never a full FQDN. - TXT values are verbatim — no escaped quoting; Azure handles the 255-char segmentation (this differs from Route 53).
- CNAME-at-apex and apex-NS overrides are rejected at plan time (DNS forbids the former; Azure manages the latter).
Requirements
| Requirement | Version |
|---|---|
| Terraform / OpenTofu | >= 1.6 |
hashicorp/azurerm | >= 4.0, < 5.0 |
Security notes
- An
azurerm_dns_zoneis a public zone — anyone on the internet can query it. For internal/split-horizon names use an Azure private DNS zone instead; there is no encryption knob for public DNS, the meaningful control is public vs private. - Publish a CAA record set (
caa_records) to restrict which CAs may issue certificates for the domain — a cheap, high-value hardening step. - Use TXT records for SPF/DKIM/DMARC to lock down email spoofing.
- The deploying principal needs the DNS Zone Contributor role (or equivalent) on the resource group to create zones and record sets.
License
Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).
Usage code & full reference unlock after purchase
The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.
- Usage
- Inputs
- Outputs
Related modules
Azure Private DNS Zone
A self-contained Azure Private DNS zone with virtual-network links and optional record sets for private name resolution across VNets and Private Endpoints - VM auto-registration off by default.
Akamai Edge DNS Zone
Authoritative Edge DNS zone with full recordset management on Akamai's DDoS-resilient anycast network.
Akamai GTM Failover/Weighted Domain
Global Traffic Management domain with datacenters and failover or weighted-round-robin properties plus liveness tests.
Cloud DNS Zones & Records
Public/private managed zones with record sets, DNSSEC, forwarding and peering configs.
Cloudflare DNS & WAF
Zone DNS records, security settings, and managed WAF rulesets for a Cloudflare zone - provider v5 ready.
DNS Zone & Traffic Steering
Public/private DNS zones with record sets, failover/geo steering policies and health-check probes.