Starting with the PowerDNS Authoritative Server, each served zone can have "metadata". Such metadata determines how this zone behaves in certain circumstances.
![]() | Warning |
---|---|
Domain metadata is only available for DNSSEC capable backends! Make sure to enable the proper '-dnssec' setting to benefit, and to have performed the DNSSEC schema update. |
Each metadata item is described elsewhere in the documentation, and the following settings are available:
Use this named TSIG key to retrieve this zone from its master.
Script to be used to edit incoming AXFRs.
Determines if this zone operates in NSEC3 'narrow' mode.
NSEC3 parameters of a DNSSEC zone. Will be used to synthesize the NSEC3PARAM record. If present, NSEC3 is used, if not present, zones default to NSEC.
This zone carries DNSSEC RRSIGs (signatures), and is presigned.
When serving this zone, modify the SOA serial number in one of several ways. Mostly useful to get slaves to re-transfer a zone regularly to get fresh RRSIGs.
Allow these named TSIG keys to AXFR this zone.