The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Inspect DNS role stateGet-WindowsFeature -Name DNS,RSAT-DNS-Server | Select-Object Name, InstallStateView examples
Inspect DnsServer moduleGet-Module -ListAvailable -Name DnsServer | Select-Object Name, Version, PathView examples
List hosted zonesGet-DnsServerZone -ComputerName 'dns01.corp.example'View examples
Inspect one zoneGet-DnsServerZone -ComputerName 'dns01.corp.example' -Name 'corp.example' | Format-List *View examples
Read an A recordGet-DnsServerResourceRecord -ComputerName ` 'dns01.corp.example' -ZoneName 'corp.example' -Name ` 'app01' -RRType AView examples
Query a chosen serverResolve-DnsName -Name 'app01.corp.example' -Type A ` -Server 'dns01.corp.example' -DnsOnlyView examples
Preview an AD zoneAdd-DnsServerPrimaryZone -ComputerName 'dns01' -Name ` 'apps.corp.example' -ReplicationScope Domain ` -DynamicUpdate Secure -WhatIfView examples
Preview a reverse zoneAdd-DnsServerPrimaryZone -ComputerName 'dns01' ` -NetworkId '192.0.2.0/24' -ReplicationScope Domain ` -DynamicUpdate Secure -WhatIfView examples
Preview A and PTR recordsAdd-DnsServerResourceRecordA -ComputerName 'dns01' ` -ZoneName 'corp.example' -Name 'app01' -IPv4Address ` '192.0.2.40' -CreatePtr -WhatIfView examples
Preview a CNAMEAdd-DnsServerResourceRecordCName -ComputerName 'dns01' ` -ZoneName 'corp.example' -Name 'portal' -HostNameAlias ` 'app01.corp.example' -WhatIfView examples
Preview exact record removalRemove-DnsServerResourceRecord -ComputerName 'dns01' ` -ZoneName 'corp.example' -RRType A -Name 'app01' ` -RecordData '192.0.2.40' -WhatIfView examples
Inspect zone agingGet-DnsServerZoneAging -ComputerName ` 'dns01.corp.example' -Name 'corp.example'View examples
Preview aging settingsSet-DnsServerZoneAging -ComputerName 'dns01' -Name ` 'corp.example' -Aging $true -NoRefreshInterval ` 7.00:00:00 -RefreshInterval 7.00:00:00 -WhatIfView examples
Inspect forwardersGet-DnsServerForwarder -ComputerName ` 'dns01.corp.example'View examples
Inspect recursion policyGet-DnsServerRecursion -ComputerName ` 'dns01.corp.example'View examples
Preview zone exportExport-DnsServerZone -ComputerName 'dns01.corp.example' ` -Name 'corp.example' -FileName ` 'corp-example-audit.txt' -WhatIfView examples
Inspect DNSSEC settingsGet-DnsServerDnsSecZoneSetting -ComputerName ` 'dns01.corp.example' -ZoneName 'corp.example'View examples
Read recent DNS eventsGet-WinEvent -FilterHashtable @{LogName='DNS Server'; ` StartTime=(Get-Date).AddHours(-2)} -MaxEvents 100View examples

Windows DNS is often both a name-resolution service and an Active Directory dependency, so a small change can affect authentication, replication, and every client using the namespace. These commands target Windows Server 2016 through Windows Server 2025 and Windows PowerShell 5.1 with the DnsServer module from the DNS Server role or RSAT. Read-only queries may run with delegated access; changes normally require an elevated session and DNS or domain administrative rights. AD-integrated zones require a domain-joined DNS server and healthy directory replication. Remote commands require firewall and management connectivity to the named server. Installing the DNS role normally needs no restart, but use Get-WindowsFeature to inspect RestartNeeded. Replace all example names and addresses after validating ownership, replication scope, reverse zones, TTLs, and rollback. WhatIf only previews cmdlets that explicitly support it; it does not test replication, downstream caching, delegation, client behavior, or every server-side validation.

Step by step

Detailed examples

01

Confirm role, module, privileges, and remote path

Use Windows PowerShell 5.1 on a supported Windows Server or an administrative workstation with RSAT DNS tools. Get commands may work with delegated read rights; configuration requires an elevated session and suitable DNS or domain permissions. ComputerName targets the DNS service remotely and therefore needs name resolution, RPC/CIM connectivity allowed by policy, and authentication. AD-integrated operations also require domain membership and healthy Active Directory replication. Installing DNS with Install-WindowsFeature DNS -IncludeManagementTools ordinarily does not require a restart, but the returned RestartNeeded value is authoritative. Installation is intentionally not automated here.

Read-only readiness check
$target = 'dns01.corp.example'
Get-WindowsFeature -ComputerName $target -Name DNS,RSAT-DNS-Server |
  Select-Object Name, InstallState
Get-Module -ListAvailable -Name DnsServer |
  Select-Object Name, Version, Path
Test-NetConnection -ComputerName $target -Port 135
Back to quick reference ↑
02

Build an authoritative zone inventory before changing data

Zone type, Active Directory integration, replication scope, dynamic-update mode, and DNSSEC state determine both risk and rollback. Query the intended authoritative server explicitly; otherwise a local default can hide differences between replicas. Snapshot the exact zone object and compare authoritative servers when diagnosing replication rather than treating one server as the whole namespace.

Inventory zones and one critical namespace
$server = 'dns01.corp.example'
Get-DnsServerZone -ComputerName $server |
  Sort-Object ZoneName |
  Select-Object ZoneName, ZoneType, IsDsIntegrated, ReplicationScope, DynamicUpdate, IsSigned
Get-DnsServerZone -ComputerName $server -Name 'corp.example' | Format-List *
Back to quick reference ↑
03

Design zone ownership and replication scope deliberately

ReplicationScope applies to AD-integrated zones: Domain stores the zone in the domain DNS application partition, while Forest broadens replication. Secure dynamic updates are available only for AD-integrated zones. A file-backed zone uses ZoneFile instead and has different replication and backup behavior. Reverse-zone creation has classful boundary behavior for some IPv4 prefixes, so verify the generated zone name. WhatIf validates cmdlet binding and previews intent, but it cannot prove AD replication health, delegation correctness, or client reachability.

Preview forward and reverse AD-integrated zones
$server = 'dns01.corp.example'
Add-DnsServerPrimaryZone -ComputerName $server -Name 'apps.corp.example' `
  -ReplicationScope Domain -DynamicUpdate Secure -WhatIf
Add-DnsServerPrimaryZone -ComputerName $server -NetworkId '192.0.2.0/24' `
  -ReplicationScope Domain -DynamicUpdate Secure -WhatIf
Back to quick reference ↑
04

Identify exact record sets and preserve forward-reverse consistency

An owner can have multiple records of the same type. Read the current RRset and use owner, type, and record data when removing a single value. CreatePtr only creates a PTR when the matching reverse lookup zone exists on that server. Avoid AllowUpdateAny unless its security consequences are explicitly accepted. For updates, retain the original record object and use Set-DnsServerResourceRecord with cloned old and new objects; the cmdlet cannot change record name or type. WhatIf previews supported record mutations but cannot detect all application-level dependencies or cached answers.

Review and preview a paired A/PTR addition
$server = 'dns01.corp.example'
$zone = 'corp.example'
Get-DnsServerResourceRecord -ComputerName $server -ZoneName $zone -Name 'app01' -RRType A
Get-DnsServerZone -ComputerName $server | Where-Object IsReverseLookupZone
Add-DnsServerResourceRecordA -ComputerName $server -ZoneName $zone `
  -Name 'app01' -IPv4Address '192.0.2.40' -CreatePtr -TimeToLive 01:00:00 -WhatIf
Preview removal of one exact value
Remove-DnsServerResourceRecord -ComputerName 'dns01.corp.example' `
  -ZoneName 'corp.example' -RRType A -Name 'app01' `
  -RecordData '192.0.2.40' -WhatIf
Back to quick reference ↑
05

Treat aging and scavenging as a coordinated retention policy

Aging timestamps dynamic records; scavenging can later delete records whose timestamp exceeds the no-refresh plus refresh intervals. Static records have a zero timestamp unless deliberately aged. Enabling zone aging alone does not guarantee a particular server will scavenge, and aggressively aging legacy or infrastructure records can cause outages. Ensure the refresh interval is not shorter than the longest registration refresh period, inventory timestamp-zero records, align DHCP lease and DNS update ownership, stage the change, and monitor before any manual scavenging. No service restart is normally required.

Audit timestamps before previewing zone aging
$server = 'dns01.corp.example'
$zone = 'corp.example'
Get-DnsServerZoneAging -ComputerName $server -Name $zone
Get-DnsServerResourceRecord -ComputerName $server -ZoneName $zone |
  Group-Object { if ($_.Timestamp) { 'Timestamped' } else { 'Static' } }
Set-DnsServerZoneAging -ComputerName $server -Name $zone -Aging $true `
  -NoRefreshInterval 7.00:00:00 -RefreshInterval 7.00:00:00 -WhatIf
Back to quick reference ↑
06

Inspect recursion and forwarding as an availability and trust boundary

Server-level forwarders are used for names the server cannot answer locally, and Set-DnsServerForwarder replaces the existing IP address list. Recursion controls whether clients can ask the server to resolve nonauthoritative names. Before changing either, inventory conditional forwarders, root hints, firewall paths, encrypted upstream requirements, and every current address. WhatIf coverage varies by cmdlet and version; even a supported preview cannot contact-test new upstream resolvers or predict cache behavior, so use staged change control and direct queries from representative networks.

Read the effective forwarding and recursion configuration
$server = 'dns01.corp.example'
Get-DnsServerForwarder -ComputerName $server | Format-List *
Get-DnsServerRecursion -ComputerName $server | Format-List *
Get-DnsServerZone -ComputerName $server |
  Where-Object ZoneType -EQ 'Forwarder' |
  Select-Object ZoneName, MasterServers
Back to quick reference ↑
07

Capture evidence and understand what a zone export is not

Export-DnsServerZone writes on the remote DNS server, normally below C:\Windows\System32\dns; FileName is not a local workstation path. For AD-integrated zones, the exported troubleshooting representation is not the same as a file-backed zone file and is not a complete Active Directory or DNS Server disaster-recovery backup. DNSSEC signing changes require separate key lifecycle, parent DS, trust-anchor, rollover, and recovery planning. Do not sign or unsign a production zone from a generic recipe. WhatIf can preview the export request, but verification requires checking the resulting file and an approved backup process.

Preview an audit export and inspect signing metadata
$server = 'dns01.corp.example'
$zone = 'corp.example'
Export-DnsServerZone -ComputerName $server -Name $zone `
  -FileName 'corp-example-audit.txt' -WhatIf
Get-DnsServerDnsSecZoneSetting -ComputerName $server -ZoneName $zone
Back to quick reference ↑
08

Verify authority, client resolution, caches, and events separately

A successful query through the normal client resolver does not prove every authoritative replica is correct, and a direct authoritative response does not prove delegations or client paths work. Query each intended server directly, compare record data and TTL, then query through representative clients. Resolve-DnsName is read-only. Clearing a server or client cache is an active, broad mutation and Clear-DnsServerCache does not offer a universal safety simulation; avoid it during diagnosis unless stale cache is proven and the impact is approved. Correlate failures with the DNS Server event log and AD replication health.

Compare two authoritative replicas and recent events
$name = 'app01.corp.example'
'dns01.corp.example','dns02.corp.example' | ForEach-Object {
  $server = $_
  Resolve-DnsName -Name $name -Type A -Server $server -DnsOnly |
    Select-Object @{n='Server';e={$server}}, Name, Type, IPAddress, TTL
}
Get-WinEvent -ComputerName 'dns01.corp.example' `
  -FilterHashtable @{LogName='DNS Server'; StartTime=(Get-Date).AddHours(-2)} `
  -MaxEvents 100
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. MicrosoftDnsServer PowerShell modulelearn.microsoft.com
  2. MicrosoftAdd-DnsServerPrimaryZonelearn.microsoft.com
  3. MicrosoftAdd-DnsServerResourceRecordlearn.microsoft.com
  4. MicrosoftSet-DnsServerZoneAginglearn.microsoft.com
  5. MicrosoftDNS aging and scavenginglearn.microsoft.com
  6. MicrosoftValidate and secure DNS responses using DNSSEClearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback