# DNS Zones

<a id="get-api-v1-accounts-username-dns-domain"></a>
#### `GET /api/v1/accounts/{username}/dns/{domain}`

*Get DNS zone for a domain*

Returns the full DNS zone including all records for an owned domain.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |
| `domain` | string | yes | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_DNSZoneResponse_` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {
    "domain": "example.com",
    "records": [
      "..."
    ],
    "serial": 0
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/accounts/{username}/dns/{domain}
```

---

<a id="get-api-v1-accounts-username-dns-domain-dnssec"></a>
#### `GET /api/v1/accounts/{username}/dns/{domain}/dnssec`

*Get DNSSEC status*

Returns whether DNSSEC is active and the public DS / DNSKEY material.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |
| `domain` | string | yes | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_DNSSECStatusResponse_` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {
    "domain": "example.com",
    "ds_records": [
      "..."
    ],
    "enabled": false,
    "keys": [
      "..."
    ]
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/accounts/{username}/dns/{domain}/dnssec
```

---

<a id="post-api-v1-accounts-username-dns-domain-dnssec-disable"></a>
#### `POST /api/v1/accounts/{username}/dns/{domain}/dnssec/disable`

*Disable DNSSEC*

Remove the signing keys and revert the zone to unsigned.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |
| `domain` | string | yes | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_DNSSECStatusResponse_` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {
    "domain": "example.com",
    "ds_records": [
      "..."
    ],
    "enabled": false,
    "keys": [
      "..."
    ]
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/accounts/{username}/dns/{domain}/dnssec/disable
```

---

<a id="post-api-v1-accounts-username-dns-domain-dnssec-enable"></a>
#### `POST /api/v1/accounts/{username}/dns/{domain}/dnssec/enable`

*Enable DNSSEC*

Generate a KSK + ZSK with ECDSA-P256-SHA256 and activate signing.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |
| `domain` | string | yes | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_DNSSECStatusResponse_` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {
    "domain": "example.com",
    "ds_records": [
      "..."
    ],
    "enabled": false,
    "keys": [
      "..."
    ]
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/accounts/{username}/dns/{domain}/dnssec/enable
```

---

<a id="post-api-v1-accounts-username-dns-domain-records"></a>
#### `POST /api/v1/accounts/{username}/dns/{domain}/records`

*Add DNS record*

Insert a new A / AAAA / CNAME / MX / TXT / SRV / CAA record.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |
| `domain` | string | yes | — |

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `content` | string | yes | — |
| `name` | string | yes | — |
| `port` | integer | no | — |
| `priority` | integer | no | — |
| `record_type` | DNSRecordType | yes | enum: `A`, `AAAA`, `CNAME`, `MX`, `TXT`, `NS`, `SRV`, `CAA`, `SOA`, `PTR` |
| `ttl` | integer | no | default `3600`; minimum=60.0; maximum=86400.0 |
| `weight` | integer | no | — |

**Request body example:**

```json
{
  "content": "string",
  "name": "string",
  "port": 0,
  "priority": 0,
  "record_type": "A",
  "ttl": 3600,
  "weight": 0
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_DNSRecordResponse_` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {
    "content": "string",
    "id": 0,
    "name": "string",
    "port": "...",
    "priority": "...",
    "record_type": "...",
    "ttl": 0,
    "weight": "..."
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/accounts/{username}/dns/{domain}/records
```

---

<a id="delete-api-v1-accounts-username-dns-domain-records-record-id"></a>
#### `DELETE /api/v1/accounts/{username}/dns/{domain}/records/{record_id}`

*Delete DNS record*

Remove a record by id. Returns a confirmation message only.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |
| `domain` | string | yes | — |
| `record_id` | integer | yes | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `MessageResponse` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "message": "string",
  "status": "success"
}
```

**cURL example:**

```bash
curl -X DELETE \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/accounts/{username}/dns/{domain}/records/{record_id}
```

---

<a id="put-api-v1-accounts-username-dns-domain-records-record-id"></a>
#### `PUT /api/v1/accounts/{username}/dns/{domain}/records/{record_id}`

*Update DNS record*

Modify content / TTL / priority for an existing record id.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |
| `domain` | string | yes | — |
| `record_id` | integer | yes | — |

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `content` | string | no | — |
| `port` | integer | no | — |
| `priority` | integer | no | — |
| `ttl` | integer | no | — |
| `weight` | integer | no | — |

**Request body example:**

```json
{
  "content": "string",
  "port": 0,
  "priority": 0,
  "ttl": 60.0,
  "weight": 0
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_DNSRecordResponse_` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {
    "content": "string",
    "id": 0,
    "name": "string",
    "port": "...",
    "priority": "...",
    "record_type": "...",
    "ttl": 0,
    "weight": "..."
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X PUT \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/accounts/{username}/dns/{domain}/records/{record_id}
```

---

<a id="post-api-v1-accounts-username-dns-domain-zone"></a>
#### `POST /api/v1/accounts/{username}/dns/{domain}/zone`

*Create / bootstrap DNS zone for a domain*

Idempotent: re-runs on a provisioned zone return the existing records. A zone created here is signed with DNSSEC like a zone created with the account; its mail records follow the account's `setup_mail_dns` switch. Used by the panel's 'Create Zone' CTA when a 404 `DNS_ZONE_NOT_FOUND` is detected (e.g. migration imports).

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `username` | string | yes | — |
| `domain` | string | yes | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_DNSZoneResponse_` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {
    "domain": "example.com",
    "records": [
      "..."
    ],
    "serial": 0
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/accounts/{username}/dns/{domain}/zone
```

---
