Skip to content

Setup

With outgoing zone transfers, you can keep Cloudflare as your primary DNS provider and use one or more secondary providers for increased availability and fault tolerance.

Aspects to consider

DNS-only CNAME records

As explained in DNS record types, Cloudflare uses a process called CNAME flattening to return the final IP address instead of the CNAME target. CNAME flattening improves performance and is also what allows you to set a CNAME record on the zone apex.

Depending on the settings you have, when you use DNS-only CNAME records with outgoing zone transfers, you can expect the following:

  • For DNS-only CNAME records on the zone apex, Cloudflare will always transfer out the flattened IP addresses.
  • For DNS-only CNAME records on subdomains, Cloudflare will only transfer out flattened IP addresses if the setting Flatten all CNAMEs is enabled.

Proxied records

For each proxied DNS record in your zone, Cloudflare will transfer out two A and two AAAA records.

These records correspond to the Cloudflare IP addresses used for proxying traffic.

Before you begin

Make sure your account team has enabled your zone for outgoing zone transfers.

Review your existing DNS records to make sure all of them have the desired Proxy status.

If using the API, you may also want to locate your Zone and Account IDs.


1. Create TSIG (optional)

A Transaction Signature (TSIG) authenticates communication between a primary and secondary DNS server.

While optional, this step is highly recommended.

To create a TSIG using the dashboard:

  1. Log in to the Cloudflare dashboard and select your account.
  2. Go to Manage Account > Configurations.
  3. Select DNS Zone Transfers.
  4. For TSIG, select Create.
  5. Enter the following information:
    • TSIG name: The name of the TSIG object using domain name syntax (more details in RFC 8945 section 4.2).
    • Secret (optional): Get a shared secret to add to your third-party nameservers. If left blank, this field generates a random secret.
    • Algorithm: Choose a TSIG signing algorithm.
  6. Select Create.

2. Create Peer DNS Server (optional)

You only need to create a peer DNS server if you want:

  • Your secondary nameservers to receive NOTIFYs for changes to your Cloudflare DNS records.
  • A TSIG to sign zone transfer requests and NOTIFYs.

To create a peer using the dashboard:

  1. Log in to the Cloudflare dashboard and select your account.
  2. Go to Manage Account > Configurations.
  3. Select DNS Zone Transfers.
  4. For Peer DNS servers, select Create.
  5. Enter the following information, paying particular attention to:
    • IP: If configured, specifies where Cloudflare sends NOTIFY requests to.
    • Port: Specifies the IP Port for the NOTIFY IP.
    • Enable incremental (IXFR) zone transfers: Does not apply when you are using Cloudflare as your primary DNS provider (Cloudflare zones always accept IXFR requests).
    • Link an existing TSIG: If desired, link the TSIG you previously created.
  6. Select Create.

If you previously created a peer DNS server, you should link it to your primary zone.

To link a primary zone to a peer using the dashboard:

  1. Log in to the Cloudflare dashboard.
  2. Select your account and zone.
  3. Go to DNS > Settings.
  4. For DNS Zone Transfers, select Manage linked peers.
  5. Select a peer.
  6. Select Save.

4. Update your secondary DNS provider

Your secondary DNS provider should send zone transfer requests (via AXFR or IXFR) to this IP on port 53 and from the IP address specified in your peer configuration.

It should also have updated Access Control Lists (ACLs) to prevent NOTIFY messages sent from Cloudflare IP ranges from being blocked.

5. Add secondary nameservers within Cloudflare

Using the information from your secondary DNS provider, create NS records on your zone apex listing your secondary nameservers.

By default, Cloudflare ignores NS records added to the zone apex. To modify this behavior, enable multi-provider DNS:

  1. Log in to the Cloudflare dashboard.
  2. Select your account and zone.
  3. Go to DNS > Settings.
  4. Enable Multi-provider DNS.

6. Enable outgoing zone transfers

When you enable outgoing zone transfers, this will send a DNS NOTIFY message to your secondary DNS provider.

  1. Log in to the Cloudflare dashboard.
  2. Select your account and zone.
  3. Go to DNS > Settings.
  4. For Outgoing Zone Transfers, switch the toggle to On.

7. Add secondary nameservers to registrar

At your registrar, add the nameservers of your secondary DNS provider.