Configuring a full (authoritative) zone
A "full setup" delegates DNS authority to CIS. You update your domain’s name servers at your registrar so CIS becomes the authoritative DNS provider for your domain. This can be applied to a root domain (example.com) or
a subdomain (sub.example.com) if needed.
To configure a full (authoritiative) zone, follow these steps:
-
Prepare your domain:
- Ensure you own the domain or subdomain.
- Identify your current DNS provider or registrar.
- Gather all existing DNS records (A, AAAA, MX, TXT, CNAME, DKIM, SPF, CAA, etc.) that must be preserved.
- Disable DNSSEC at your registrar if it is currently enabled.
- Remove or resolve any conflicting records at the registrar that could prevent delegation.
-
Add your domain to CIS:
- Log in to the IBM Cloud Console and open your CIS instance.
- Navigate to Domains > Add domain.
- Enter your domain or subdomain name and select Full setup (authoritative DNS).
- Proceed to add the domain.
-
Import or recreate DNS records in CIS:
- Go to DNS > Records in the CIS dashboard.
- Import existing DNS records from your previous provider if available.
- If import is not available, manually add all necessary records, including:
- A and AAAA records
- MX and TXT records (including SPF, DKIM)
- CAA and other service-specific records
- Verify that all records are correct before updating name servers.
Missing or incorrect records cause service interruptions once CIS becomes authoritative.
-
Update name servers at your registrar:
- In the CIS console, note the assigned name servers (for example,
ns004.name.cloud.ibm.com,ns005.name.cloud.ibm.com). - Log in to your domain registrar.
- Locate your domain’s DNS / Nameserver settings.
- Replace the existing name servers with the CIS name servers exactly as provided.
- Save the changes.
Ensure name servers are entered accurately. Typos or omissions break DNS resolution.
- In the CIS console, note the assigned name servers (for example,
-
Wait for propagation and verify:
- DNS changes can take 24–48 hours, or in rare cases up to 72 hours, to propagate globally.
- Use
digornslookupto confirm that the domain now resolves with CIS name servers. - The CIS console automatically detects when delegation is complete, and the domain status changes from Pending to Active.
-
Optionally, after propagation, re-enable DNSSEC at your registrar if required. Use the DS records provided by CIS to complete DNSSEC setup.
-
Confirm DNS functionality:
- Test your domain’s website, email, and any other services.
- Ensure all DNS records (for example, A, MX, TXT, CAA) are resolving correctly.
- Troubleshoot any issues by checking records in CIS or verifying name server settings at your registrar.