The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Inspect DNS role state | Get-WindowsFeature -Name DNS,RSAT-DNS-Server |
Select-Object Name, InstallState | View examples |
| Inspect DnsServer module | Get-Module -ListAvailable -Name DnsServer |
Select-Object Name, Version, Path | View examples |
| List hosted zones | Get-DnsServerZone -ComputerName 'dns01.corp.example' | View examples |
| Inspect one zone | Get-DnsServerZone -ComputerName 'dns01.corp.example' -Name 'corp.example' |
Format-List * | View examples |
| Read an A record | Get-DnsServerResourceRecord -ComputerName `
'dns01.corp.example' -ZoneName 'corp.example' -Name `
'app01' -RRType A | View examples |
| Query a chosen server | Resolve-DnsName -Name 'app01.corp.example' -Type A `
-Server 'dns01.corp.example' -DnsOnly | View examples |
| Preview an AD zone | Add-DnsServerPrimaryZone -ComputerName 'dns01' -Name `
'apps.corp.example' -ReplicationScope Domain `
-DynamicUpdate Secure -WhatIf | View examples |
| Preview a reverse zone | Add-DnsServerPrimaryZone -ComputerName 'dns01' `
-NetworkId '192.0.2.0/24' -ReplicationScope Domain `
-DynamicUpdate Secure -WhatIf | View examples |
| Preview A and PTR records | Add-DnsServerResourceRecordA -ComputerName 'dns01' `
-ZoneName 'corp.example' -Name 'app01' -IPv4Address `
'192.0.2.40' -CreatePtr -WhatIf | View examples |
| Preview a CNAME | Add-DnsServerResourceRecordCName -ComputerName 'dns01' `
-ZoneName 'corp.example' -Name 'portal' -HostNameAlias `
'app01.corp.example' -WhatIf | View examples |
| Preview exact record removal | Remove-DnsServerResourceRecord -ComputerName 'dns01' `
-ZoneName 'corp.example' -RRType A -Name 'app01' `
-RecordData '192.0.2.40' -WhatIf | View examples |
| Inspect zone aging | Get-DnsServerZoneAging -ComputerName `
'dns01.corp.example' -Name 'corp.example' | View examples |
| Preview aging settings | Set-DnsServerZoneAging -ComputerName 'dns01' -Name `
'corp.example' -Aging $true -NoRefreshInterval `
7.00:00:00 -RefreshInterval 7.00:00:00 -WhatIf | View examples |
| Inspect forwarders | Get-DnsServerForwarder -ComputerName `
'dns01.corp.example' | View examples |
| Inspect recursion policy | Get-DnsServerRecursion -ComputerName `
'dns01.corp.example' | View examples |
| Preview zone export | Export-DnsServerZone -ComputerName 'dns01.corp.example' `
-Name 'corp.example' -FileName `
'corp-example-audit.txt' -WhatIf | View examples |
| Inspect DNSSEC settings | Get-DnsServerDnsSecZoneSetting -ComputerName `
'dns01.corp.example' -ZoneName 'corp.example' | View examples |
| Read recent DNS events | Get-WinEvent -FilterHashtable @{LogName='DNS Server'; `
StartTime=(Get-Date).AddHours(-2)} -MaxEvents 100 | View examples |
Windows DNS is often both a name-resolution service and an Active Directory dependency, so a small change can affect authentication, replication, and every client using the namespace. These commands target Windows Server 2016 through Windows Server 2025 and Windows PowerShell 5.1 with the DnsServer module from the DNS Server role or RSAT. Read-only queries may run with delegated access; changes normally require an elevated session and DNS or domain administrative rights. AD-integrated zones require a domain-joined DNS server and healthy directory replication. Remote commands require firewall and management connectivity to the named server. Installing the DNS role normally needs no restart, but use Get-WindowsFeature to inspect RestartNeeded. Replace all example names and addresses after validating ownership, replication scope, reverse zones, TTLs, and rollback. WhatIf only previews cmdlets that explicitly support it; it does not test replication, downstream caching, delegation, client behavior, or every server-side validation.
Step by step
Detailed examples
Confirm role, module, privileges, and remote path
Use Windows PowerShell 5.1 on a supported Windows Server or an administrative workstation with RSAT DNS tools. Get commands may work with delegated read rights; configuration requires an elevated session and suitable DNS or domain permissions. ComputerName targets the DNS service remotely and therefore needs name resolution, RPC/CIM connectivity allowed by policy, and authentication. AD-integrated operations also require domain membership and healthy Active Directory replication. Installing DNS with Install-WindowsFeature DNS -IncludeManagementTools ordinarily does not require a restart, but the returned RestartNeeded value is authoritative. Installation is intentionally not automated here.
$target = 'dns01.corp.example'
Get-WindowsFeature -ComputerName $target -Name DNS,RSAT-DNS-Server |
Select-Object Name, InstallState
Get-Module -ListAvailable -Name DnsServer |
Select-Object Name, Version, Path
Test-NetConnection -ComputerName $target -Port 135 Build an authoritative zone inventory before changing data
Zone type, Active Directory integration, replication scope, dynamic-update mode, and DNSSEC state determine both risk and rollback. Query the intended authoritative server explicitly; otherwise a local default can hide differences between replicas. Snapshot the exact zone object and compare authoritative servers when diagnosing replication rather than treating one server as the whole namespace.
$server = 'dns01.corp.example'
Get-DnsServerZone -ComputerName $server |
Sort-Object ZoneName |
Select-Object ZoneName, ZoneType, IsDsIntegrated, ReplicationScope, DynamicUpdate, IsSigned
Get-DnsServerZone -ComputerName $server -Name 'corp.example' | Format-List * Design zone ownership and replication scope deliberately
ReplicationScope applies to AD-integrated zones: Domain stores the zone in the domain DNS application partition, while Forest broadens replication. Secure dynamic updates are available only for AD-integrated zones. A file-backed zone uses ZoneFile instead and has different replication and backup behavior. Reverse-zone creation has classful boundary behavior for some IPv4 prefixes, so verify the generated zone name. WhatIf validates cmdlet binding and previews intent, but it cannot prove AD replication health, delegation correctness, or client reachability.
$server = 'dns01.corp.example'
Add-DnsServerPrimaryZone -ComputerName $server -Name 'apps.corp.example' `
-ReplicationScope Domain -DynamicUpdate Secure -WhatIf
Add-DnsServerPrimaryZone -ComputerName $server -NetworkId '192.0.2.0/24' `
-ReplicationScope Domain -DynamicUpdate Secure -WhatIf Identify exact record sets and preserve forward-reverse consistency
An owner can have multiple records of the same type. Read the current RRset and use owner, type, and record data when removing a single value. CreatePtr only creates a PTR when the matching reverse lookup zone exists on that server. Avoid AllowUpdateAny unless its security consequences are explicitly accepted. For updates, retain the original record object and use Set-DnsServerResourceRecord with cloned old and new objects; the cmdlet cannot change record name or type. WhatIf previews supported record mutations but cannot detect all application-level dependencies or cached answers.
$server = 'dns01.corp.example'
$zone = 'corp.example'
Get-DnsServerResourceRecord -ComputerName $server -ZoneName $zone -Name 'app01' -RRType A
Get-DnsServerZone -ComputerName $server | Where-Object IsReverseLookupZone
Add-DnsServerResourceRecordA -ComputerName $server -ZoneName $zone `
-Name 'app01' -IPv4Address '192.0.2.40' -CreatePtr -TimeToLive 01:00:00 -WhatIf Remove-DnsServerResourceRecord -ComputerName 'dns01.corp.example' `
-ZoneName 'corp.example' -RRType A -Name 'app01' `
-RecordData '192.0.2.40' -WhatIf Treat aging and scavenging as a coordinated retention policy
Aging timestamps dynamic records; scavenging can later delete records whose timestamp exceeds the no-refresh plus refresh intervals. Static records have a zero timestamp unless deliberately aged. Enabling zone aging alone does not guarantee a particular server will scavenge, and aggressively aging legacy or infrastructure records can cause outages. Ensure the refresh interval is not shorter than the longest registration refresh period, inventory timestamp-zero records, align DHCP lease and DNS update ownership, stage the change, and monitor before any manual scavenging. No service restart is normally required.
$server = 'dns01.corp.example'
$zone = 'corp.example'
Get-DnsServerZoneAging -ComputerName $server -Name $zone
Get-DnsServerResourceRecord -ComputerName $server -ZoneName $zone |
Group-Object { if ($_.Timestamp) { 'Timestamped' } else { 'Static' } }
Set-DnsServerZoneAging -ComputerName $server -Name $zone -Aging $true `
-NoRefreshInterval 7.00:00:00 -RefreshInterval 7.00:00:00 -WhatIf Inspect recursion and forwarding as an availability and trust boundary
Server-level forwarders are used for names the server cannot answer locally, and Set-DnsServerForwarder replaces the existing IP address list. Recursion controls whether clients can ask the server to resolve nonauthoritative names. Before changing either, inventory conditional forwarders, root hints, firewall paths, encrypted upstream requirements, and every current address. WhatIf coverage varies by cmdlet and version; even a supported preview cannot contact-test new upstream resolvers or predict cache behavior, so use staged change control and direct queries from representative networks.
$server = 'dns01.corp.example'
Get-DnsServerForwarder -ComputerName $server | Format-List *
Get-DnsServerRecursion -ComputerName $server | Format-List *
Get-DnsServerZone -ComputerName $server |
Where-Object ZoneType -EQ 'Forwarder' |
Select-Object ZoneName, MasterServers Capture evidence and understand what a zone export is not
Export-DnsServerZone writes on the remote DNS server, normally below C:\Windows\System32\dns; FileName is not a local workstation path. For AD-integrated zones, the exported troubleshooting representation is not the same as a file-backed zone file and is not a complete Active Directory or DNS Server disaster-recovery backup. DNSSEC signing changes require separate key lifecycle, parent DS, trust-anchor, rollover, and recovery planning. Do not sign or unsign a production zone from a generic recipe. WhatIf can preview the export request, but verification requires checking the resulting file and an approved backup process.
$server = 'dns01.corp.example'
$zone = 'corp.example'
Export-DnsServerZone -ComputerName $server -Name $zone `
-FileName 'corp-example-audit.txt' -WhatIf
Get-DnsServerDnsSecZoneSetting -ComputerName $server -ZoneName $zone Verify authority, client resolution, caches, and events separately
A successful query through the normal client resolver does not prove every authoritative replica is correct, and a direct authoritative response does not prove delegations or client paths work. Query each intended server directly, compare record data and TTL, then query through representative clients. Resolve-DnsName is read-only. Clearing a server or client cache is an active, broad mutation and Clear-DnsServerCache does not offer a universal safety simulation; avoid it during diagnosis unless stale cache is proven and the impact is approved. Correlate failures with the DNS Server event log and AD replication health.
$name = 'app01.corp.example'
'dns01.corp.example','dns02.corp.example' | ForEach-Object {
$server = $_
Resolve-DnsName -Name $name -Type A -Server $server -DnsOnly |
Select-Object @{n='Server';e={$server}}, Name, Type, IPAddress, TTL
}
Get-WinEvent -ComputerName 'dns01.corp.example' `
-FilterHashtable @{LogName='DNS Server'; StartTime=(Get-Date).AddHours(-2)} `
-MaxEvents 100 Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- MicrosoftDnsServer PowerShell modulelearn.microsoft.com
- MicrosoftAdd-DnsServerPrimaryZonelearn.microsoft.com
- MicrosoftAdd-DnsServerResourceRecordlearn.microsoft.com
- MicrosoftSet-DnsServerZoneAginglearn.microsoft.com
- MicrosoftDNS aging and scavenginglearn.microsoft.com
- MicrosoftValidate and secure DNS responses using DNSSEClearn.microsoft.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



