IaC Bazaar
AzureLive-tested

Azure Public DNS Zone & Records

An Azure public DNS zone plus a map-driven set of record sets - A, AAAA, CNAME, TXT, MX, NS, CAA and SRV - with relative naming, verbatim TXT values, and apex footgun guards.

terraformAzure#azure

Compare DNS & Traffic Management across clouds →

Part of: Azure Production Landing Zone

azure-dns-zoneterraform v1.7

Verification

Live-tested

Really deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan pending (Checkov)
  • Plan test superseded by live test

Provenance

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-06-30 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o azure-dns-zone-1.0.1.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/azure-dns-zone/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle azure-dns-zone-1.0.1.sigstore.json \
  azure-dns-zone-1.0.1.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "85222e5469fef66f3b65a6d6a8459256dc8434d93686d7806318f15f163d24ac  azure-dns-zone-1.0.1.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "dns_zone" {
  source  = "www.iac-bazaar.com/iac-bazaar/azure-dns-zone/azure"
  version = "1.0.1"
}

Free module — Terraform/OpenTofu downloads it with no token or setup. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.

This module is in the Free band, and a free account sees the contract of every Free module — no subscription needed.

Documentation

azure-dns-zone

Azure public DNS zone (azurerm_dns_zone) plus a clean, map-driven set of record sets — A, AAAA, CNAME, TXT, MX, NS, CAA and SRV. Works with Terraform and OpenTofu (>= 1.6), azurerm provider >= 4.0, < 5.0. The module consumes an existing resource group (DNS zones are global, so there is no location to set).

Each record type maps to its own azurerm resource via for_each, so addressing is stable and editing one entry never churns the others. The fiddly Azure-isms are handled or documented for you:

  • Record names are relative to the zone — use "@" (the default) for the apex or a label like "www"; never a full FQDN.
  • TXT values are verbatim — no escaped quoting; Azure handles the 255-char segmentation (this differs from Route 53).
  • CNAME-at-apex and apex-NS overrides are rejected at plan time (DNS forbids the former; Azure manages the latter).

Requirements

RequirementVersion
Terraform / OpenTofu>= 1.6
hashicorp/azurerm>= 4.0, < 5.0

Security notes

  • An azurerm_dns_zone is a public zone — anyone on the internet can query it. For internal/split-horizon names use an Azure private DNS zone instead; there is no encryption knob for public DNS, the meaningful control is public vs private.
  • Publish a CAA record set (caa_records) to restrict which CAs may issue certificates for the domain — a cheap, high-value hardening step.
  • Use TXT records for SPF/DKIM/DMARC to lock down email spoofing.
  • The deploying principal needs the DNS Zone Contributor role (or equivalent) on the resource group to create zones and record sets.

License

Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference unlock after purchase

The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.

  • Usage
  • Inputs
  • Outputs

Related modules