DNS Management & Nameservers

Mastering BIND DNS Configuration: A Step-by-Step Guide to Setup, Troubleshooting, and Error Resolution

By the Domain India teamPublished 10 min read
Knowledge base article
Contents (9 sections)

BIND (named) is the classic open-source DNS server. You run it when you want your own server to answer authoritatively for your domains, for example as ns1.yourbusiness.com on a VPS. This guide sets up an authoritative BIND server on a current Linux distribution, validates it, signs it with DNSSEC, and fixes the errors you are most likely to meet. It applies to a server you control, such as a VPS or dedicated server, not to shared hosting.

Key takeaways

Install BIND (bind on AlmaLinux and Rocky Linux, bind9 on Ubuntu and Debian), set recursion no for an authoritative server, define each zone in the config, write the zone file with a dated serial, and check both with named-checkconf -z and named-checkzone before every reload. Open port 53 on TCP and UDP, run at least two nameservers, and register them as child nameservers at your registrar. Most websites never need their own DNS server: hosting nameservers or your DNS provider do the job with less risk.

1. Do you need your own DNS server?

Running BIND makes you responsible for your domain's availability: if your DNS server is down, your website and email are unreachable, even if the web server is fine.

Your situationBest choice
Website and email on shared hostingUse your hosting nameservers and edit records in the control panel
Records managed by a DNS service such as CloudflareEdit records at that service
You run your own servers and want full control, or you resell hosting under your brandRun BIND on at least two servers, with child nameservers
You need internal names for an office or lab networkBIND with views, or a local resolver

If you only need to change where your website or email points, see how to change your domain DNS settings instead.

2. Install BIND

CentOS has reached end of life. For a new server, use AlmaLinux or Rocky Linux 9, or Ubuntu 24.04 LTS or Debian 12.

AlmaLinux and Rocky Linux:

bash
sudo dnf install bind bind-utils
sudo systemctl enable --now named

Main config: /etc/named.conf. Zone files: /var/named/.

Ubuntu and Debian:

bash
sudo apt update
sudo apt install bind9 bind9-utils bind9-dnsutils
sudo systemctl enable --now named

Main config: /etc/bind/named.conf, which includes named.conf.options and named.conf.local. Keep zone files that BIND must write to, such as signed zones, in /var/lib/bind/.

Check the version with named -v. The examples below use features available in the BIND versions shipped with those distributions.

3. Configure the options for an authoritative server

An authoritative server answers only for its own zones. It must not resolve other domains for the whole internet: an open resolver is abused in DNS amplification attacks.

text
options {
    directory "/var/named";          // /var/cache/bind on Ubuntu and Debian
    listen-on port 53 { any; };
    listen-on-v6 port 53 { any; };
    recursion no;                    // authoritative only
    allow-query { any; };            // anyone may ask about your zones
    allow-transfer { none; };        // no zone copies unless you allow them
    version "not disclosed";
    rate-limit { responses-per-second 10; };
};
  • recursion no is the most important line. Older guides show recursion yes with allow-query { any; }, which creates an open resolver.
  • rate-limit (response rate limiting) reduces the damage if someone uses your server to flood a victim with replies.
  • allow-transfer stays none until you add a secondary server (section 6).

4. Create a zone

Declare the zone in /etc/named.conf (AlmaLinux and Rocky) or /etc/bind/named.conf.local (Ubuntu and Debian):

text
zone "example.com" {
    type primary;
    file "example.com.zone";
};

On Ubuntu and Debian, give the full path instead: file "/var/lib/bind/example.com.zone";. On very old BIND versions, primary is written master. Then create the zone file:

text
$TTL 3600
@       IN  SOA ns1.example.com. hostmaster.example.com. (
            2026092301 ; serial, YYYYMMDDnn
            3600       ; refresh
            900        ; retry
            1209600    ; expire
            300 )      ; negative-answer TTL
        IN  NS   ns1.example.com.
        IN  NS   ns2.example.com.
@       IN  A    192.0.2.10
ns1     IN  A    192.0.2.53
ns2     IN  A    198.51.100.53
www     IN  CNAME example.com.
@       IN  MX   10 mail.example.com.
mail    IN  A    192.0.2.25
@       IN  TXT  "v=spf1 mx -all"

Replace the documentation addresses with your own. Key points:

  • The serial must go up every time you change the file, or secondary servers ignore the change. The date plus a two-digit counter is the usual pattern.
  • The second field of the SOA line is an email address with the @ written as a dot.
  • Every name ending in a dot is absolute. Leaving the final dot off ns1.example.com. turns it into ns1.example.com.example.com.

On AlmaLinux and Rocky Linux, set the owner so BIND can read the file: sudo chown root:named /var/named/example.com.zone, then sudo restorecon -v /var/named/example.com.zone for SELinux. On Ubuntu and Debian, run sudo chown bind:bind /var/lib/bind/example.com.zone.

5. Validate, reload and test

Never reload BIND without checking first:

  1. Check the config and every zone it loads.
    Run sudo named-checkconf -z. It prints each zone's serial, or the file and line number of any error.
  2. Check one zone file.
    Run sudo named-checkzone example.com /var/named/example.com.zone, using your zone file's real path.
  3. Reload.
    Run sudo rndc reload example.com for one zone, or sudo rndc reload for all.
  4. Ask your server directly.
    Run dig @127.0.0.1 example.com A +norec and look for the aa (authoritative answer) flag.
  5. Open the firewall.
    DNS uses UDP and TCP port 53: sudo firewall-cmd --permanent --add-service=dns && sudo firewall-cmd --reload on AlmaLinux and Rocky, or sudo ufw allow 53 on Ubuntu.
  6. Test from outside.
    From another machine, run dig @your_server_ip example.com A +norec.

Logs go to the system journal: sudo journalctl -u named -e.

6. Nameservers, glue records and a secondary server

A domain needs at least two nameservers, ideally on different servers and networks, so one failure does not take the domain offline.

  • Secondary server. On the primary, allow transfers to the secondary's IP only, for example allow-transfer { 198.51.100.53; }; and also-notify { 198.51.100.53; }; in the zone. On the secondary, declare the zone as type secondary; with the primary's IP. For transfers over the internet, protect them with a TSIG key.
  • Child nameservers. If your nameservers are named inside your own domain, such as ns1.example.com, the registry must store their IP addresses as glue records. See registering and managing child name servers.
  • Delegation. Finally, set the domain's nameservers at your registrar to your two nameservers. See how do I change my nameservers.

Test the full path from the root down with dig +trace example.com.

7. Sign the zone with DNSSEC

DNSSEC signs your records so resolvers can detect forged answers. Current BIND versions manage keys automatically with a policy:

text
zone "example.com" {
    type primary;
    file "example.com.zone";
    dnssec-policy default;
    inline-signing yes;
};

After a reload, BIND creates the keys and a signed copy of the zone. Get the DS record to give your registrar with:

bash
dig @127.0.0.1 example.com DNSKEY | dnssec-dsfromkey -f - example.com

Add the DS record at your registrar only after the signed zone answers correctly from every nameserver. A wrong or stale DS record makes the whole domain fail for validating resolvers. Older guides use dnssec-keygen, dnssec-signzone and auto-dnssec maintain; the policy method replaces them.

8. Common errors and fixes

Error or symptomCauseFix
unknown optionA typo, or an option your BIND version does not supportCheck spelling against the documentation for your version
unexpected token near end of fileA missing semicolon or closing braceEvery statement and block ends with a semicolon
when using 'view' statements, all zones must be in viewsSome zones sit outside any viewMove every zone into a view, or remove the views
zone not loaded due to errorsThe zone file has a syntax problemRun named-checkzone and fix the reported line
permission denied on a zone fileWrong owner or SELinux labelFix ownership and run restorecon on AlmaLinux and Rocky
Change not visible on the secondaryThe serial was not increasedRaise the serial and reload the primary
REFUSED for your own domainThe zone is not loaded, or allow-query blocks the clientCheck the journal and allow-query
SERVFAIL after enabling DNSSECThe DS at the registrar does not match your keysCompare dnssec-dsfromkey output with the registrar's DS

Even after a fix, resolvers may keep the old answer until its TTL expires. Lower the TTL a day before planned changes.

Running your own cPanel/WHM server?

On a cPanel server, WHM manages the DNS server and its zone files for you, and recent cPanel versions default to PowerDNS rather than BIND. Use WHM's DNS functions instead of editing zone files by hand, or WHM may overwrite your changes.

9. Where Domain India fits

On Domain India shared hosting (cPanel, DirectAdmin, Webuzo), you cannot run BIND or change server configuration. You manage records in your control panel instead; see managing DNS records.

To run your own DNS server, you need a server of your own. A Domain India VPS is self-managed with full root access, so BIND, its firewall and its updates are yours to run. Plan for two servers if the DNS must stay up.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

The plan card shows the live Domain India list price, excluding 18% GST.

How do I check a BIND configuration for errors?

Run named-checkconf -z to check the main configuration and every zone it loads, and named-checkzone followed by the zone name and file to check one zone file. Fix any reported line before you reload.

Should recursion be on in BIND?

Not on an authoritative server that is reachable from the internet. Set recursion no. Recursion open to everyone creates an open resolver that attackers use for amplification attacks.

Why does my DNS change not show on the secondary server?

The SOA serial was not increased. Secondaries copy a zone only when its serial is higher than theirs. Raise the serial, reload the primary, and check both servers with dig SOA.

Which port does BIND use?

Port 53 on both UDP and TCP. TCP is needed for large answers, DNSSEC and zone transfers, so open both in the firewall.

Can I run BIND on Domain India shared hosting?

No. Shared hosting does not allow server software such as BIND. Manage your records in the control panel's DNS editor, or run BIND on a VPS, where you have full root access.

How many nameservers does a domain need?

At least two, ideally on different servers and networks, so the domain stays reachable if one fails.

Ready to run your own DNS? Set up the servers with this guide, register your child name servers, then point the domain at them. If you only need to change a record, managing DNS records is the quicker route.

A server for your own DNS

Self-managed KVM VPS with full root access, so you can run BIND, its firewall and its updates your way.

See VPS plans

Ready when you are

Find your domain

Search domains

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app