ActorStack.dev

What a registry zone file contains, and what it never will

A zone file is a delegation record: which domains exist in a TLD and where each one points its nameservers. It holds no registrant, no registrar, no dates and none of the domain's own records — and knowing that is what makes the six zone-file Actors readable.

By Oswaldo Carabano7 min read

Short answer

A registry zone file is the authoritative list of every domain delegated in a top-level domain, together with the nameservers each one points at and, where present, its DNSSEC delegation-signer records. That is the whole of it. A zone file contains no registrant name, no email address, no registrar, no registration date, no expiry date, and none of the domain's own A, MX or TXT records — those are published by the domain's nameservers rather than by the registry. Every answer these six Actors give and every limit they state follows from that shape: delegation is visible and certain, ownership is invisible, and anything about a website is somewhere else entirely.

Key points

  • A zone file lists every domain delegated in a top-level domain and the nameservers each one points at, which is the registry's own authoritative record.
  • Registrant names, email addresses, registrars, registration dates and expiry dates are absent from a zone file entirely, so no zone-derived tool can return them.
  • A domain's own A, MX and TXT records live on its nameservers rather than in the registry zone, which is why a zone file cannot show what a site is built with.
  • DNSSEC delegation-signer records are in the zone, which makes DNSSEC adoption one of the few security properties measurable straight from it.
  • Delegation is the only thing a zone file proves, and every claim built on one is either that fact or an inference from it.
On this page5 sections

Six of the Actors in this catalogue read the same thing. Knowing exactly what that thing is explains every answer they give and every limit they state.

The registry's own record of delegation

A zone file is the authoritative list of what exists inside one top-level domain. When a registry delegates example.com, it publishes a record saying that the name exists and naming the servers that answer for it. The zone file is the accumulation of those records — not a crawl, not a sample, not an observation. It is the registry stating what it has done.

What is actually in a zone file

RecordWhat it says
NSThis domain exists and delegates to these nameservers
DSThe parent vouches for this domain's DNSSEC signing key
Glue A / AAAAThe address of a nameserver that lives inside this same zone

That is close to the whole of it. Delegation, the signing vouch, and the minimum addressing needed to make the delegation resolvable.

What is not, and will not be

No registrant name. No email address. No registrar. No registration date, no expiry date, no status. Those live in registrar and registry databases reached through WHOIS or RDAP, which is a different source with different access rules — and, under the agreement that provides zone data, one that cannot be queried at scale alongside it.

Why a site's own records are somewhere else

A zone file says where a domain delegates. It does not say what those nameservers answer. The domain's A, MX, TXT and CNAME records are published by its nameservers, one level down, which is why a zone file cannot tell you where a site is hosted, where its mail goes or what platform it runs on.

What follows for every tool built on one

Delegation is certain, so “this domain exists” is a fact. Absence is ambiguous, so “this domain is free” is a verdict with an error rate. Change is visible only by comparing two snapshots, which is why a delegation change is detectable and a registration date is not. Every product built on this source is some arrangement of those three facts.

Frequently asked questions

What is a DNS zone file?
A zone file is the authoritative list of every domain delegated in a top-level domain, with the nameservers each one points at. For a registry, it is the record of what exists in that TLD and where each name is answered from.
Does a zone file say who owns a domain?
No. Registrant names, email addresses and registrars are not in a zone file at any point. Ownership information lives in registrar and registry databases reached through WHOIS or RDAP, which is a different source with different access rules.
Can a zone file tell me what a website runs on?
No. A site's platform is configured through A and CNAME records, which are published by the domain's own nameservers rather than by the registry. A zone file carries the delegation and stops there, so the technology behind a site is not visible in it.
Why does a zone file contain DNSSEC records?
Because the delegation-signer record is part of the delegation itself: it is what the parent zone publishes to vouch for the child's signing key. That makes DNSSEC one of the few security properties measurable directly from registry data.

Sources

Every URL below was requested and returned a page on the date shown.

  1. Platform docschecked 18 Sept 2026
    RFC 1035 — Domain Names: Implementation and SpecificationIETF
  2. Platform docschecked 18 Sept 2026
    Centralized Zone Data ServiceICANN
  3. Platform docschecked 18 Sept 2026
    RFC 4034 — Resource Records for the DNS Security ExtensionsIETF
  4. Law or regulatorchecked 18 Sept 2026
    Root Zone Database — the delegation record for every TLDIANA
Racks of network equipment in a dimly lit server room, lit blue by their indicators.
DomainsMeasured

What dns_provider can tell you

The nameserver identifies who runs the DNS for 69.1% of domains. It does not identify what a site is built with, and the measurement that settled that question is worth seeing.

5 min
Printed notices and leaflets stapled to a wooden hoarding on a street.
DomainsReference

gTLDs and ccTLDs

Country-code TLDs are run outside ICANN's contracts, so their zone files are not available through the zone data service at any price. The gap matters most in exactly the namespaces a startup cares about.

6 min
A desk with stacked legal reference books, loose documents and a newspaper.
DomainsExplainer

ICANN CZDS access

Access to gTLD zone files is granted one TLD at a time, by each registry operator, under an agreement that shapes what a product built on the data is allowed to look like.

7 min