Skip to main content
resource · azure

Azure DNS Zone

schedulable
no
category
networking-services

Does ZopNight manage Azure DNS Zone?

Azure DNS bills each public zone a monthly fee plus query charges, so a single zone costs little; the signal value is larger than the spend. ZopNight discovers zones via Resource Graph with record-set counts, mapping service dependencies and surfacing abandoned domains that keep resolving long after their service died.

Rules that fire on Azure DNS Zone

no live rules

No active rule family targets Azure DNS Zone today. Rules that used to are retired, and retired rules publish no pages and fire no findings. Scheduling and permissions coverage are unaffected.

Browse every live recommendation for this platform →

At a glance

Azure DNS Zone coverage facts.
Field Value
Scheduling notesdiscovery only.

Azure DNS zones host public domain records, billed per zone plus queries. Costs are small but zones map service dependencies and reveal abandoned domains.

Per-zone plus per-query, a small steady meter

A public DNS zone charges two ways: a flat amount per hosted zone per month, and a charge on the queries it answers. Neither figure is large for a typical estate, and no single zone will ever dominate an invoice. The meter’s interesting property is its persistence. A zone bills identically whether it fronts a production platform or a marketing site retired years ago, because DNS has no idle state. Records resolve until someone deletes them.

Record sets as a dependency map

Discovered via Azure Resource Graph with record-set counts, providing topology and hygiene context. A zone’s records are effectively a public statement of what an organization runs: every CNAME into a CDN, every A record at a load balancer, every TXT verification hints at a service somewhere with its own cost. ZopNight treats zones as read-only context, discovery only with no schedulable lifecycle, but the record-set count alone separates active zones from husks. A zone with 2 records (the default NS and SOA) is holding a name and doing nothing else.

Zombie zones and dangling records

Two hygiene patterns matter more than the direct cost. Abandoned zones for lapsed projects keep billing their small fee indefinitely and clutter the estate. More seriously, dangling records are a subdomain-takeover risk: entries pointing at public IPs or hostnames that were released: whoever acquires the released target inherits your name pointing at it. Cleaning up a dead environment should end at its DNS entries, and rarely does.

Auditing public DNS zones

Azure portal → DNS zones lists every hosted zone with its record count and resource group. Opening a zone shows each record set and its targets, which is where dangling entries are confirmed. Cross-referencing targets against live resources is exactly the join ZopNight’s topology data makes cheap.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·