BIND (named) is the classic open-source DNS server. You run it when you want your own server to answer authoritatively for your domains, for example as ns1.yourbusiness.com on a VPS. This guide sets up an authoritative BIND server on a current Linux distribution, validates it, signs it with DNSSEC, and fixes the errors you are most likely to meet. It applies to a server you control, such as a VPS or dedicated server, not to shared hosting.
Install BIND (bind on AlmaLinux and Rocky Linux, bind9 on Ubuntu and Debian), set recursion no for an authoritative server, define each zone in the config, write the zone file with a dated serial, and check both with named-checkconf -z and named-checkzone before every reload. Open port 53 on TCP and UDP, run at least two nameservers, and register them as child nameservers at your registrar. Most websites never need their own DNS server: hosting nameservers or your DNS provider do the job with less risk.
1. Do you need your own DNS server?
Running BIND makes you responsible for your domain's availability: if your DNS server is down, your website and email are unreachable, even if the web server is fine.
| Your situation | Best choice |
|---|---|
| Website and email on shared hosting | Use your hosting nameservers and edit records in the control panel |
| Records managed by a DNS service such as Cloudflare | Edit records at that service |
| You run your own servers and want full control, or you resell hosting under your brand | Run BIND on at least two servers, with child nameservers |
| You need internal names for an office or lab network | BIND with views, or a local resolver |
If you only need to change where your website or email points, see how to change your domain DNS settings instead.
2. Install BIND
CentOS has reached end of life. For a new server, use AlmaLinux or Rocky Linux 9, or Ubuntu 24.04 LTS or Debian 12.
AlmaLinux and Rocky Linux:
sudo dnf install bind bind-utils
sudo systemctl enable --now namedMain config: /etc/named.conf. Zone files: /var/named/.
Ubuntu and Debian:
sudo apt update
sudo apt install bind9 bind9-utils bind9-dnsutils
sudo systemctl enable --now namedMain config: /etc/bind/named.conf, which includes named.conf.options and named.conf.local. Keep zone files that BIND must write to, such as signed zones, in /var/lib/bind/.
Check the version with named -v. The examples below use features available in the BIND versions shipped with those distributions.
3. Configure the options for an authoritative server
An authoritative server answers only for its own zones. It must not resolve other domains for the whole internet: an open resolver is abused in DNS amplification attacks.
options {
directory "/var/named"; // /var/cache/bind on Ubuntu and Debian
listen-on port 53 { any; };
listen-on-v6 port 53 { any; };
recursion no; // authoritative only
allow-query { any; }; // anyone may ask about your zones
allow-transfer { none; }; // no zone copies unless you allow them
version "not disclosed";
rate-limit { responses-per-second 10; };
};recursion nois the most important line. Older guides showrecursion yeswithallow-query { any; }, which creates an open resolver.rate-limit(response rate limiting) reduces the damage if someone uses your server to flood a victim with replies.allow-transferstaysnoneuntil you add a secondary server (section 6).
4. Create a zone
Declare the zone in /etc/named.conf (AlmaLinux and Rocky) or /etc/bind/named.conf.local (Ubuntu and Debian):
zone "example.com" {
type primary;
file "example.com.zone";
};On Ubuntu and Debian, give the full path instead: file "/var/lib/bind/example.com.zone";. On very old BIND versions, primary is written master. Then create the zone file:
$TTL 3600
@ IN SOA ns1.example.com. hostmaster.example.com. (
2026092301 ; serial, YYYYMMDDnn
3600 ; refresh
900 ; retry
1209600 ; expire
300 ) ; negative-answer TTL
IN NS ns1.example.com.
IN NS ns2.example.com.
@ IN A 192.0.2.10
ns1 IN A 192.0.2.53
ns2 IN A 198.51.100.53
www IN CNAME example.com.
@ IN MX 10 mail.example.com.
mail IN A 192.0.2.25
@ IN TXT "v=spf1 mx -all"Replace the documentation addresses with your own. Key points:
- The serial must go up every time you change the file, or secondary servers ignore the change. The date plus a two-digit counter is the usual pattern.
- The second field of the SOA line is an email address with the
@written as a dot. - Every name ending in a dot is absolute. Leaving the final dot off
ns1.example.com.turns it intons1.example.com.example.com.
On AlmaLinux and Rocky Linux, set the owner so BIND can read the file: sudo chown root:named /var/named/example.com.zone, then sudo restorecon -v /var/named/example.com.zone for SELinux. On Ubuntu and Debian, run sudo chown bind:bind /var/lib/bind/example.com.zone.
5. Validate, reload and test
Never reload BIND without checking first:
- Check the config and every zone it loads.Run
sudo named-checkconf -z. It prints each zone's serial, or the file and line number of any error. - Check one zone file.Run
sudo named-checkzone example.com /var/named/example.com.zone, using your zone file's real path. - Reload.Run
sudo rndc reload example.comfor one zone, orsudo rndc reloadfor all. - Ask your server directly.Run
dig @127.0.0.1 example.com A +norecand look for theaa(authoritative answer) flag. - Open the firewall.DNS uses UDP and TCP port 53:
sudo firewall-cmd --permanent --add-service=dns && sudo firewall-cmd --reloadon AlmaLinux and Rocky, orsudo ufw allow 53on Ubuntu. - Test from outside.From another machine, run
dig @your_server_ip example.com A +norec.
Logs go to the system journal: sudo journalctl -u named -e.
6. Nameservers, glue records and a secondary server
A domain needs at least two nameservers, ideally on different servers and networks, so one failure does not take the domain offline.
- Secondary server. On the primary, allow transfers to the secondary's IP only, for example
allow-transfer { 198.51.100.53; };andalso-notify { 198.51.100.53; };in the zone. On the secondary, declare the zone astype secondary;with the primary's IP. For transfers over the internet, protect them with a TSIG key. - Child nameservers. If your nameservers are named inside your own domain, such as
ns1.example.com, the registry must store their IP addresses as glue records. See registering and managing child name servers. - Delegation. Finally, set the domain's nameservers at your registrar to your two nameservers. See how do I change my nameservers.
Test the full path from the root down with dig +trace example.com.
7. Sign the zone with DNSSEC
DNSSEC signs your records so resolvers can detect forged answers. Current BIND versions manage keys automatically with a policy:
zone "example.com" {
type primary;
file "example.com.zone";
dnssec-policy default;
inline-signing yes;
};After a reload, BIND creates the keys and a signed copy of the zone. Get the DS record to give your registrar with:
dig @127.0.0.1 example.com DNSKEY | dnssec-dsfromkey -f - example.comAdd the DS record at your registrar only after the signed zone answers correctly from every nameserver. A wrong or stale DS record makes the whole domain fail for validating resolvers. Older guides use dnssec-keygen, dnssec-signzone and auto-dnssec maintain; the policy method replaces them.
8. Common errors and fixes
| Error or symptom | Cause | Fix |
|---|---|---|
| unknown option | A typo, or an option your BIND version does not support | Check spelling against the documentation for your version |
| unexpected token near end of file | A missing semicolon or closing brace | Every statement and block ends with a semicolon |
| when using 'view' statements, all zones must be in views | Some zones sit outside any view | Move every zone into a view, or remove the views |
| zone not loaded due to errors | The zone file has a syntax problem | Run named-checkzone and fix the reported line |
| permission denied on a zone file | Wrong owner or SELinux label | Fix ownership and run restorecon on AlmaLinux and Rocky |
| Change not visible on the secondary | The serial was not increased | Raise the serial and reload the primary |
| REFUSED for your own domain | The zone is not loaded, or allow-query blocks the client | Check the journal and allow-query |
| SERVFAIL after enabling DNSSEC | The DS at the registrar does not match your keys | Compare dnssec-dsfromkey output with the registrar's DS |
Even after a fix, resolvers may keep the old answer until its TTL expires. Lower the TTL a day before planned changes.
On a cPanel server, WHM manages the DNS server and its zone files for you, and recent cPanel versions default to PowerDNS rather than BIND. Use WHM's DNS functions instead of editing zone files by hand, or WHM may overwrite your changes.
9. Where Domain India fits
On Domain India shared hosting (cPanel, DirectAdmin, Webuzo), you cannot run BIND or change server configuration. You manage records in your control panel instead; see managing DNS records.
To run your own DNS server, you need a server of your own. A Domain India VPS is self-managed with full root access, so BIND, its firewall and its updates are yours to run. Plan for two servers if the DNS must stay up.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
The plan card shows the live Domain India list price, excluding 18% GST.
How do I check a BIND configuration for errors?
Run named-checkconf -z to check the main configuration and every zone it loads, and named-checkzone followed by the zone name and file to check one zone file. Fix any reported line before you reload.
Should recursion be on in BIND?
Not on an authoritative server that is reachable from the internet. Set recursion no. Recursion open to everyone creates an open resolver that attackers use for amplification attacks.
Why does my DNS change not show on the secondary server?
The SOA serial was not increased. Secondaries copy a zone only when its serial is higher than theirs. Raise the serial, reload the primary, and check both servers with dig SOA.
Which port does BIND use?
Port 53 on both UDP and TCP. TCP is needed for large answers, DNSSEC and zone transfers, so open both in the firewall.
Can I run BIND on Domain India shared hosting?
No. Shared hosting does not allow server software such as BIND. Manage your records in the control panel's DNS editor, or run BIND on a VPS, where you have full root access.
How many nameservers does a domain need?
At least two, ideally on different servers and networks, so the domain stays reachable if one fails.
Ready to run your own DNS? Set up the servers with this guide, register your child name servers, then point the domain at them. If you only need to change a record, managing DNS records is the quicker route.
Self-managed KVM VPS with full root access, so you can run BIND, its firewall and its updates your way.
See VPS plans