Skip to content
Start here

Settings

SettingsZone

Show DNS Settings
GET/zones/{zone_id}/dns_settings
Update DNS Settings
PATCH/zones/{zone_id}/dns_settings
ModelsExpand Collapse
ZoneGetResponse object { flatten_all_cnames, foundation_dns, internal_dns, 6 more }
flatten_all_cnames: boolean

Whether to flatten all CNAME records in the zone. Note that, due to DNS limitations, a CNAME record at the zone apex will always be flattened.

Deprecatedfoundation_dns: boolean

foundation_dns is deprecated. Use nameservers.type: cloudflare.advanced to turn on Advanced Nameservers and cloudflare.standard to turn it off. This field will be removed in a future API version.

Deprecated. Use nameservers.type to configure Advanced Nameservers.

internal_dns: object { reference_zone_id }

Settings for this internal zone.

reference_zone_id: optional string

The ID of the zone to fallback to.

multi_provider: boolean

Whether to enable multi-provider DNS, which causes Cloudflare to activate the zone even when non-Cloudflare NS records exist, and to respect NS records at the zone apex during outbound zone transfers.

nameservers: object { type } or object { type, ns_set } or object { nameserver_set_id, type }

Controls the nameservers through which the zone is available.

One of the following:
DNSSettingsZoneNameserversCloudflare object { type }
type: "cloudflare.standard" or "cloudflare.advanced"

Nameserver type.

One of the following:
"cloudflare.standard"
"cloudflare.advanced"
DNSSettingsZoneNameserversCustomExisting object { type, ns_set }
type: "custom.account" or "custom.tenant" or "custom.zone"

Nameserver type.

One of the following:
"custom.account"
"custom.tenant"
"custom.zone"
ns_set: optional number

Configured nameserver set number to use for this zone.

maximum5
minimum1
DNSSettingsZoneNameserversCustomSet object { nameserver_set_id, type }
nameserver_set_id: string

Identifier of the account-owned Custom Nameserver Set to use for this zone.

maxLength32
minLength32
type: "custom"

Nameserver type.

ns_ttl: number

The time to live (TTL) of the zone’s nameserver (NS) records.

maximum86400
minimum30
secondary_overrides: boolean

Allows a Secondary DNS zone to use (proxied) override records and CNAME flattening at the zone apex.

soa: object { expire, min_ttl, mname, 4 more }

Components of the zone’s SOA record.

expire: optional number

Time in seconds of being unable to query the primary server after which secondary servers should stop serving the zone.

maximum2419200
minimum86400
min_ttl: optional number

The time to live (TTL) for negative caching of records within the zone.

maximum86400
minimum60
mname: optional string

The primary nameserver, which may be used for outbound zone transfers. If null, a Cloudflare-assigned value will be used.

refresh: optional number

Time in seconds after which secondary servers should re-check the SOA record to see if the zone has been updated.

maximum86400
minimum600
retry: optional number

Time in seconds after which secondary servers should retry queries after the primary server was unresponsive.

maximum86400
minimum600
rname: optional string

The email address of the zone administrator, with the first label representing the local part of the email address.

ttl: optional number

The time to live (TTL) of the SOA record itself.

maximum86400
minimum300
zone_mode: "standard" or "cdn_only" or "dns_only"

Whether the zone mode is a regular or CDN/DNS only zone.

One of the following:
"standard"
"cdn_only"
"dns_only"
ZoneEditResponse object { flatten_all_cnames, foundation_dns, internal_dns, 6 more }
flatten_all_cnames: boolean

Whether to flatten all CNAME records in the zone. Note that, due to DNS limitations, a CNAME record at the zone apex will always be flattened.

Deprecatedfoundation_dns: boolean

foundation_dns is deprecated. Use nameservers.type: cloudflare.advanced to turn on Advanced Nameservers and cloudflare.standard to turn it off. This field will be removed in a future API version.

Deprecated. Use nameservers.type to configure Advanced Nameservers.

internal_dns: object { reference_zone_id }

Settings for this internal zone.

reference_zone_id: optional string

The ID of the zone to fallback to.

multi_provider: boolean

Whether to enable multi-provider DNS, which causes Cloudflare to activate the zone even when non-Cloudflare NS records exist, and to respect NS records at the zone apex during outbound zone transfers.

nameservers: object { type } or object { type, ns_set } or object { nameserver_set_id, type }

Controls the nameservers through which the zone is available.

One of the following:
DNSSettingsZoneNameserversCloudflare object { type }
type: "cloudflare.standard" or "cloudflare.advanced"

Nameserver type.

One of the following:
"cloudflare.standard"
"cloudflare.advanced"
DNSSettingsZoneNameserversCustomExisting object { type, ns_set }
type: "custom.account" or "custom.tenant" or "custom.zone"

Nameserver type.

One of the following:
"custom.account"
"custom.tenant"
"custom.zone"
ns_set: optional number

Configured nameserver set number to use for this zone.

maximum5
minimum1
DNSSettingsZoneNameserversCustomSet object { nameserver_set_id, type }
nameserver_set_id: string

Identifier of the account-owned Custom Nameserver Set to use for this zone.

maxLength32
minLength32
type: "custom"

Nameserver type.

ns_ttl: number

The time to live (TTL) of the zone’s nameserver (NS) records.

maximum86400
minimum30
secondary_overrides: boolean

Allows a Secondary DNS zone to use (proxied) override records and CNAME flattening at the zone apex.

soa: object { expire, min_ttl, mname, 4 more }

Components of the zone’s SOA record.

expire: optional number

Time in seconds of being unable to query the primary server after which secondary servers should stop serving the zone.

maximum2419200
minimum86400
min_ttl: optional number

The time to live (TTL) for negative caching of records within the zone.

maximum86400
minimum60
mname: optional string

The primary nameserver, which may be used for outbound zone transfers. If null, a Cloudflare-assigned value will be used.

refresh: optional number

Time in seconds after which secondary servers should re-check the SOA record to see if the zone has been updated.

maximum86400
minimum600
retry: optional number

Time in seconds after which secondary servers should retry queries after the primary server was unresponsive.

maximum86400
minimum600
rname: optional string

The email address of the zone administrator, with the first label representing the local part of the email address.

ttl: optional number

The time to live (TTL) of the SOA record itself.

maximum86400
minimum300
zone_mode: "standard" or "cdn_only" or "dns_only"

Whether the zone mode is a regular or CDN/DNS only zone.

One of the following:
"standard"
"cdn_only"
"dns_only"

SettingsAccount

Show DNS Settings
GET/accounts/{account_id}/dns_settings
Update DNS Settings
PATCH/accounts/{account_id}/dns_settings
ModelsExpand Collapse
AccountGetResponse object { zone_defaults, enforce_dns_only }
zone_defaults: object { flatten_all_cnames, foundation_dns, internal_dns, 6 more }

Default settings for new zones created in this account.

flatten_all_cnames: boolean

Whether to flatten all CNAME records in the zone. Note that, due to DNS limitations, a CNAME record at the zone apex will always be flattened.

Deprecatedfoundation_dns: boolean

foundation_dns is deprecated. Use nameservers.type: cloudflare.advanced to turn on Advanced Nameservers and cloudflare.standard to turn it off. This field will be removed in a future API version.

Deprecated. Use nameservers.type to configure Advanced Nameservers.

internal_dns: object { reference_zone_id }

Settings for this internal zone.

reference_zone_id: optional string

The ID of the zone to fallback to.

multi_provider: boolean

Whether to enable multi-provider DNS, which causes Cloudflare to activate the zone even when non-Cloudflare NS records exist, and to respect NS records at the zone apex during outbound zone transfers.

nameservers: object { type }

Settings determining the nameservers through which the zone should be available.

type: "cloudflare.standard" or "cloudflare.advanced" or "cloudflare.standard.random" or 2 more

Nameserver type

One of the following:
"cloudflare.standard"
"cloudflare.advanced"
"cloudflare.standard.random"
"custom.account"
"custom.tenant"
ns_ttl: number

The time to live (TTL) of the zone’s nameserver (NS) records.

maximum86400
minimum30
secondary_overrides: boolean

Allows a Secondary DNS zone to use (proxied) override records and CNAME flattening at the zone apex.

soa: object { expire, min_ttl, mname, 4 more }

Components of the zone’s SOA record.

expire: optional number

Time in seconds of being unable to query the primary server after which secondary servers should stop serving the zone.

maximum2419200
minimum86400
min_ttl: optional number

The time to live (TTL) for negative caching of records within the zone.

maximum86400
minimum60
mname: optional string

The primary nameserver, which may be used for outbound zone transfers. If null, a Cloudflare-assigned value will be used.

refresh: optional number

Time in seconds after which secondary servers should re-check the SOA record to see if the zone has been updated.

maximum86400
minimum600
retry: optional number

Time in seconds after which secondary servers should retry queries after the primary server was unresponsive.

maximum86400
minimum600
rname: optional string

The email address of the zone administrator, with the first label representing the local part of the email address.

ttl: optional number

The time to live (TTL) of the SOA record itself.

maximum86400
minimum300
zone_mode: "standard" or "cdn_only" or "dns_only"

Whether the zone mode is a regular or CDN/DNS only zone.

One of the following:
"standard"
"cdn_only"
"dns_only"
enforce_dns_only: optional boolean

When enabled, forces all proxied DNS records in the account to behave as DNS-only at the edge, regardless of each record’s individual proxy setting. Note that this account-level override does not modify the records themselves; it only affects how they are served at the edge. See more on Enforce DNS-only.

AccountEditResponse object { zone_defaults, enforce_dns_only }
zone_defaults: object { flatten_all_cnames, foundation_dns, internal_dns, 6 more }

Default settings for new zones created in this account.

flatten_all_cnames: boolean

Whether to flatten all CNAME records in the zone. Note that, due to DNS limitations, a CNAME record at the zone apex will always be flattened.

Deprecatedfoundation_dns: boolean

foundation_dns is deprecated. Use nameservers.type: cloudflare.advanced to turn on Advanced Nameservers and cloudflare.standard to turn it off. This field will be removed in a future API version.

Deprecated. Use nameservers.type to configure Advanced Nameservers.

internal_dns: object { reference_zone_id }

Settings for this internal zone.

reference_zone_id: optional string

The ID of the zone to fallback to.

multi_provider: boolean

Whether to enable multi-provider DNS, which causes Cloudflare to activate the zone even when non-Cloudflare NS records exist, and to respect NS records at the zone apex during outbound zone transfers.

nameservers: object { type }

Settings determining the nameservers through which the zone should be available.

type: "cloudflare.standard" or "cloudflare.advanced" or "cloudflare.standard.random" or 2 more

Nameserver type

One of the following:
"cloudflare.standard"
"cloudflare.advanced"
"cloudflare.standard.random"
"custom.account"
"custom.tenant"
ns_ttl: number

The time to live (TTL) of the zone’s nameserver (NS) records.

maximum86400
minimum30
secondary_overrides: boolean

Allows a Secondary DNS zone to use (proxied) override records and CNAME flattening at the zone apex.

soa: object { expire, min_ttl, mname, 4 more }

Components of the zone’s SOA record.

expire: optional number

Time in seconds of being unable to query the primary server after which secondary servers should stop serving the zone.

maximum2419200
minimum86400
min_ttl: optional number

The time to live (TTL) for negative caching of records within the zone.

maximum86400
minimum60
mname: optional string

The primary nameserver, which may be used for outbound zone transfers. If null, a Cloudflare-assigned value will be used.

refresh: optional number

Time in seconds after which secondary servers should re-check the SOA record to see if the zone has been updated.

maximum86400
minimum600
retry: optional number

Time in seconds after which secondary servers should retry queries after the primary server was unresponsive.

maximum86400
minimum600
rname: optional string

The email address of the zone administrator, with the first label representing the local part of the email address.

ttl: optional number

The time to live (TTL) of the SOA record itself.

maximum86400
minimum300
zone_mode: "standard" or "cdn_only" or "dns_only"

Whether the zone mode is a regular or CDN/DNS only zone.

One of the following:
"standard"
"cdn_only"
"dns_only"
enforce_dns_only: optional boolean

When enabled, forces all proxied DNS records in the account to behave as DNS-only at the edge, regardless of each record’s individual proxy setting. Note that this account-level override does not modify the records themselves; it only affects how they are served at the edge. See more on Enforce DNS-only.

SettingsAccountNameserver Sets

List Custom Nameserver Sets
GET/accounts/{account_id}/dns_settings/nameserver_sets
Get Custom Nameserver Set
GET/accounts/{account_id}/dns_settings/nameserver_sets/{nameserver_set_id}
Create Custom Nameserver Set
POST/accounts/{account_id}/dns_settings/nameserver_sets
Delete Custom Nameserver Set
DELETE/accounts/{account_id}/dns_settings/nameserver_sets/{nameserver_set_id}
ModelsExpand Collapse
NameserverSetListResponse = object { id, advanced, created_on, 2 more } or object { id, advanced, created_on, 2 more }
One of the following:
DNSSettingsNameserverSetStandardResponse object { id, advanced, created_on, 2 more }
id: string

Identifier for a nameserver set.

maxLength32
minLength32
advanced: false

Whether the nameserver set uses Advanced anycast groups.

created_on: string

When the nameserver set was created.

formatdate-time
ip_set: number

Selects the account-specific IP set that supplies the nameserver addresses. The account’s entitlement determines the maximum value. Nameserver sets with the same ip_set and advanced value may reuse addresses; otherwise, they use disjoint address groups.

formatint64
minimum1
nameservers: array of object { ipv4, ipv6, name }
ipv4: array of string

IPv4 addresses assigned to the nameserver.

ipv6: array of string

IPv6 addresses assigned to the nameserver.

name: string

A unique lowercase Punycode nameserver name within the set.

DNSSettingsNameserverSetAdvancedResponse object { id, advanced, created_on, 2 more }
id: string

Identifier for a nameserver set.

maxLength32
minLength32
advanced: true

Whether the nameserver set uses Advanced anycast groups.

created_on: string

When the nameserver set was created.

formatdate-time
ip_set: number

Selects the account-specific IP set that supplies the nameserver addresses. The account’s entitlement determines the maximum value. Nameserver sets with the same ip_set and advanced value may reuse addresses; otherwise, they use disjoint address groups.

formatint64
minimum1
nameservers: array of object { ipv4, ipv4_groups, ipv6, 2 more }
ipv4: array of string

IPv4 addresses assigned to the nameserver.

ipv4_groups: array of "a" or "b" or "c"

Advanced anycast group for each address in the corresponding address array. Entries have the same order as, and correspond one-to-one with, the addresses.

One of the following:
"a"
"b"
"c"
ipv6: array of string

IPv6 addresses assigned to the nameserver.

ipv6_groups: array of "a" or "b" or "c"

Advanced anycast group for each address in the corresponding address array. Entries have the same order as, and correspond one-to-one with, the addresses.

One of the following:
"a"
"b"
"c"
name: string

A unique lowercase Punycode nameserver name within the set.

NameserverSetGetResponse = object { id, advanced, created_on, 2 more } or object { id, advanced, created_on, 2 more }
One of the following:
DNSSettingsNameserverSetStandardResponse object { id, advanced, created_on, 2 more }
id: string

Identifier for a nameserver set.

maxLength32
minLength32
advanced: false

Whether the nameserver set uses Advanced anycast groups.

created_on: string

When the nameserver set was created.

formatdate-time
ip_set: number

Selects the account-specific IP set that supplies the nameserver addresses. The account’s entitlement determines the maximum value. Nameserver sets with the same ip_set and advanced value may reuse addresses; otherwise, they use disjoint address groups.

formatint64
minimum1
nameservers: array of object { ipv4, ipv6, name }
ipv4: array of string

IPv4 addresses assigned to the nameserver.

ipv6: array of string

IPv6 addresses assigned to the nameserver.

name: string

A unique lowercase Punycode nameserver name within the set.

DNSSettingsNameserverSetAdvancedResponse object { id, advanced, created_on, 2 more }
id: string

Identifier for a nameserver set.

maxLength32
minLength32
advanced: true

Whether the nameserver set uses Advanced anycast groups.

created_on: string

When the nameserver set was created.

formatdate-time
ip_set: number

Selects the account-specific IP set that supplies the nameserver addresses. The account’s entitlement determines the maximum value. Nameserver sets with the same ip_set and advanced value may reuse addresses; otherwise, they use disjoint address groups.

formatint64
minimum1
nameservers: array of object { ipv4, ipv4_groups, ipv6, 2 more }
ipv4: array of string

IPv4 addresses assigned to the nameserver.

ipv4_groups: array of "a" or "b" or "c"

Advanced anycast group for each address in the corresponding address array. Entries have the same order as, and correspond one-to-one with, the addresses.

One of the following:
"a"
"b"
"c"
ipv6: array of string

IPv6 addresses assigned to the nameserver.

ipv6_groups: array of "a" or "b" or "c"

Advanced anycast group for each address in the corresponding address array. Entries have the same order as, and correspond one-to-one with, the addresses.

One of the following:
"a"
"b"
"c"
name: string

A unique lowercase Punycode nameserver name within the set.

NameserverSetCreateResponse = object { id, advanced, created_on, 2 more } or object { id, advanced, created_on, 2 more }
One of the following:
DNSSettingsNameserverSetStandardResponse object { id, advanced, created_on, 2 more }
id: string

Identifier for a nameserver set.

maxLength32
minLength32
advanced: false

Whether the nameserver set uses Advanced anycast groups.

created_on: string

When the nameserver set was created.

formatdate-time
ip_set: number

Selects the account-specific IP set that supplies the nameserver addresses. The account’s entitlement determines the maximum value. Nameserver sets with the same ip_set and advanced value may reuse addresses; otherwise, they use disjoint address groups.

formatint64
minimum1
nameservers: array of object { ipv4, ipv6, name }
ipv4: array of string

IPv4 addresses assigned to the nameserver.

ipv6: array of string

IPv6 addresses assigned to the nameserver.

name: string

A unique lowercase Punycode nameserver name within the set.

DNSSettingsNameserverSetAdvancedResponse object { id, advanced, created_on, 2 more }
id: string

Identifier for a nameserver set.

maxLength32
minLength32
advanced: true

Whether the nameserver set uses Advanced anycast groups.

created_on: string

When the nameserver set was created.

formatdate-time
ip_set: number

Selects the account-specific IP set that supplies the nameserver addresses. The account’s entitlement determines the maximum value. Nameserver sets with the same ip_set and advanced value may reuse addresses; otherwise, they use disjoint address groups.

formatint64
minimum1
nameservers: array of object { ipv4, ipv4_groups, ipv6, 2 more }
ipv4: array of string

IPv4 addresses assigned to the nameserver.

ipv4_groups: array of "a" or "b" or "c"

Advanced anycast group for each address in the corresponding address array. Entries have the same order as, and correspond one-to-one with, the addresses.

One of the following:
"a"
"b"
"c"
ipv6: array of string

IPv6 addresses assigned to the nameserver.

ipv6_groups: array of "a" or "b" or "c"

Advanced anycast group for each address in the corresponding address array. Entries have the same order as, and correspond one-to-one with, the addresses.

One of the following:
"a"
"b"
"c"
name: string

A unique lowercase Punycode nameserver name within the set.

NameserverSetDeleteResponse object { id }
id: string

Identifier for a nameserver set.

maxLength32
minLength32

SettingsAccountViews

List Internal DNS Views
GET/accounts/{account_id}/dns_settings/views
DNS Internal View Details
GET/accounts/{account_id}/dns_settings/views/{view_id}
Create Internal DNS View
POST/accounts/{account_id}/dns_settings/views
Update Internal DNS View
PATCH/accounts/{account_id}/dns_settings/views/{view_id}
Delete Internal DNS View
DELETE/accounts/{account_id}/dns_settings/views/{view_id}
ModelsExpand Collapse
ViewListResponse object { id, created_time, modified_time, 2 more }
id: string

Identifier.

maxLength32
created_time: string

When the view was created.

formatdate-time
modified_time: string

When the view was last modified.

formatdate-time
name: string

The name of the view.

maxLength255
minLength1
zones: array of string

The list of zones linked to this view.

ViewGetResponse object { id, created_time, modified_time, 2 more }
id: string

Identifier.

maxLength32
created_time: string

When the view was created.

formatdate-time
modified_time: string

When the view was last modified.

formatdate-time
name: string

The name of the view.

maxLength255
minLength1
zones: array of string

The list of zones linked to this view.

ViewCreateResponse object { id, created_time, modified_time, 2 more }
id: string

Identifier.

maxLength32
created_time: string

When the view was created.

formatdate-time
modified_time: string

When the view was last modified.

formatdate-time
name: string

The name of the view.

maxLength255
minLength1
zones: array of string

The list of zones linked to this view.

ViewEditResponse object { id, created_time, modified_time, 2 more }
id: string

Identifier.

maxLength32
created_time: string

When the view was created.

formatdate-time
modified_time: string

When the view was last modified.

formatdate-time
name: string

The name of the view.

maxLength255
minLength1
zones: array of string

The list of zones linked to this view.

ViewDeleteResponse object { id }
id: optional string

Identifier.

maxLength32