Ends in
00
days
00
hrs
00
mins
00
secs
ENROLL NOW

💪 25% OFF on ALL Reviewers to Start Your 2026 Strong with our New Year, New Skills Sale!

Azure DNS

Last updated on December 24, 2025

Azure DNS Cheat Sheet

  • Enables you to host your DNS zone and manage your DNS records.
  • DNS zone allows you to configure a private and public DNS zone.
  • Alias recordsets:
    • A – maps the host to IPv4.
    • AAAA – maps the host to IPv6.
    • CNAME – create a record to point to another domain.
  • A limit of 20 alias record sets per resource.
  • Uses Anycast networking to route users to the closest name servers.
  • Tutorials dojo strip
  • You can monitor your DNS zone metrics using Azure Monitor.
    • QueryVolume – query traffic received.
    • RecordSetCount – the number of recordsets in your DNS.
    • RecordSetCapacityUtilization – percentage of utilization of your recordset capacity.
  • Azure Private DNS allows you to use your custom domain name in your private VNet.
  • Alias record allows you to point your naked domain or apex to a traffic manager or CDN endpoint.
  • DNS Security Policy with Threat Intelligence (GA): This is a major security update. It allows you to filter DNS queries at the virtual network level to block or alert on known malicious domains (like phishing sites) using Microsoft’s managed threat intelligence feed.
  • DNS Security Extensions (DNSSEC) for Public Zones (GA): Adds cryptographic signing to your DNS records to protect them from spoofing and cache poisoning attacks, ensuring DNS responses are authentic.
  • Azure DNS Private Resolver (GA): This is a crucial new component for hybrid scenarios. It enables reliable, bi-directional DNS query resolution between your Azure Virtual Networks and on-premises networks or other clouds, without using custom DNS servers.

Private DNS

  • Allows you to manage and resolve domain names in a virtual network.
  • Configure a split-horizon DNS to create zones with the same name.
  • It also supports all types of DNS records types: A, AAAA, CNAME, MX, PTR, SOA, SRV, and TXT.
  • A virtual network can be linked to only one private zone. But you can link multiple virtual networks to a single DNS zone.
  • Private IP space in the linked virtual network allows reverse DNS.
  • Internet resolution for Azure Private DNS zones (Preview): This feature improves hybrid resolution by allowing a Private DNS zone to forward unresolved queries to the public internet.

Azure DNS Security

  • To prevent accidental zone deletion, you can apply a ‘CanNotDelete’ lock.
  • Create a custom role to ensure it doesn’t have a zone delete permission.
  • You can deploy a DNS firewall to mitigate DNS-related security issues. You can deploy a DNS firewall using the managed DNS Security Policy to filter malicious traffic, or use DNSSEC to cryptographically sign your zones

Azure DNS Pricing

  • Billed on the number of hosted DNS zones.
  • You are charged based on the number of DNS queries received.

Validate Your Knowledge

Question 1

Question Type: Single choice

You have an Azure subscription that contains an Azure DNS zone named tutorialsdojo.com.

There is a requirement to delegate a subdomain named portal.tutorialsdojo.com to another Azure DNS zone.

What solution would satisfy the requirement?

  1. Navigate to tutorialsdojo.com and add a PTR record named portal.
  2. Navigate to tutorialsdojo.com and add an NS record named portal.
  3. Navigate to tutorialsdojo.com and add a CNAME record named portal.
  4. Navigate to tutorialsdojo.com and add a TXT record named portal.

Correct Answer: 2

Azure DNS is a hosting service for DNS domains that provides name resolution by using Microsoft Azure infrastructure. By hosting your domains in Azure, you can manage your DNS records by using the same credentials, APIs, tools, and billing as your other Azure services.

You can use the Azure portal to delegate a DNS subdomain. For example, if you own the tutorialsdojo.com domain, you can delegate a subdomain called portal to another, separate zone that you can administer separately from the tutorialsdojo.com zone.

To delegate an Azure DNS subdomain, you must first delegate your public domain to Azure DNS. Once your domain is delegated to your Azure DNS zone, you can delegate your subdomain.

You can delegate a subdomain by doing the following:

1. Create a new Azure DNS zone named portal.tutorialsdojo.com. Copy down the four nameservers as you will need them for step 2.

2. Navigate to the tutorialsdojo.com DNS zone and add an NS record named portal. Under records, enter the four nameservers from portal.tutorialsdojo.com and click ok.

3. To verify your work, open a PowerShell window and type nslookup portal.tutorialsdojo.com

Hence, this statement is correct: Navigate to tutorialsdojo.com and add an NS record named portal.

The following statements are incorrect because PTR, CNAME, and TXT records are not used to delegate an Azure DNS subdomain.

– Navigate to tutorialsdojo.com and add a PTR record named portal.

– Navigate to tutorialsdojo.com and add a CNAME record named portal.

– Navigate to tutorialsdojo.com and add a TXT record named portal.

References:
https://docs.microsoft.com/en-us/azure/dns/dns-overview
https://docs.microsoft.com/en-us/azure/dns/delegate-subdomain

Note: This question was extracted from our AZ-104 Microsoft Azure Administrator Practice Exams.

For more Azure practice exam questions with detailed explanations, check out the Tutorials Dojo Portal:

Microsoft Azure Practice Exams Tutorials Dojo

Azure DNS Cheat Sheet Resources:

https://azure.microsoft.com/en-us/services/dns/
https://docs.microsoft.com/en-us/azure/dns/dns-overview

Learn AWS with our PlayCloud Hands-On Labs

$2.99 AWS and Azure Exam Study Guide eBooks

tutorials dojo study guide eBook

New AWS Generative AI Developer Professional Course AIP-C01

AIP-C01 Exam Guide AIP-C01 examtopics AWS Certified Generative AI Developer Professional Exam Domains AIP-C01

Learn GCP By Doing! Try Our GCP PlayCloud

Learn Azure with our Azure PlayCloud

FREE AI and AWS Digital Courses

FREE AWS, Azure, GCP Practice Test Samplers

Subscribe to our YouTube Channel

Tutorials Dojo YouTube Channel

Follow Us On Linkedin

Written by: Jon Bonso

Jon Bonso is the co-founder of Tutorials Dojo, an EdTech startup and an AWS Digital Training Partner that provides high-quality educational materials in the cloud computing space. He graduated from Mapúa Institute of Technology in 2007 with a bachelor's degree in Information Technology. Jon holds 10 AWS Certifications and is also an active AWS Community Builder since 2020.

AWS, Azure, and GCP Certifications are consistently among the top-paying IT certifications in the world, considering that most companies have now shifted to the cloud. Earn over $150,000 per year with an AWS, Azure, or GCP certification!

Follow us on LinkedIn, YouTube, Facebook, or join our Slack study group. More importantly, answer as many practice exams as you can to help increase your chances of passing your certification exams on your first try!

View Our AWS, Azure, and GCP Exam Reviewers Check out our FREE courses

Our Community

~98%
passing rate
Around 95-98% of our students pass the AWS Certification exams after training with our courses.
200k+
students
Over 200k enrollees choose Tutorials Dojo in preparing for their AWS Certification exams.
~4.8
ratings
Our courses are highly rated by our enrollees from all over the world.

What our students say about us?