Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To test a DNS zone from the command line, run zonemaster-cli example.com after installing Zonemaster-CLI, or use the official Docker image with docker run -t --rm zonemaster/cli example.com. Zonemaster-CLI runs DNS validation tests through the Zonemaster-Engine library and reports findings; it does not host or change your DNS. Use its results to identify issues to investigate, not as proof by themselves that a zone is healthy or down.

What Zonemaster-CLI checks—and what it does not do

Zonemaster is an open-source DNS validation project. Zonemaster-CLI is its command-line interface to Zonemaster-Engine, the test library. The wider project also provides a Backend JSON/RPC interface and a GUI that uses that Backend. The project describes its purpose this way: “The components developed as part of the Zonemaster project will help different types of users to check domain servers for configuration errors and generate a report that will assist in fixing the errors.” Zonemaster project overview

The CLI tests DNS behavior and configuration and streams findings as test cases run. It is diagnostic software, not a DNS hosting service: it does not edit registrar, parent-zone, or DNS-provider records. You must assess each message and make any needed changes in the systems that control your domain. The project overview and CLI guide explain the main workflow, but exact test semantics belong to the relevant test-case specifications and manual page.

Choose a way to run the CLI

Method Setup Files and network
Local installation Install Zonemaster-LDNS, then Zonemaster-Engine, then Zonemaster-CLI. Run it in your local environment; ensure IPv6 is available if you want IPv6 testing.
Docker Use the documented zonemaster/cli image. Ensure the Docker daemon has IPv6 enabled for IPv6 testing. Mount custom files, such as root hints, into the container so the CLI can read them.

The official documentation describes both local installation and Docker; it does not establish that one is faster or more reliable. Zonemaster-CLI documentation

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Forvencer Server Book, 2 Zipper Pocket, Server Books for Waitress
  • Upgraded Two Zipper Pockets: Forvencer server books feature two secure zipper pockets for better organization of coins, cash, and receipts, ensuring that everything you collect has a safe and secure place
  • Smart Storage & Quick Access: Designed with 8 multi-functional compartments, the right side includes a guest receipt pad, while the left has a money pocket, ticket pocket, and credit card slot. Two small clear pockets store bills, receipts, and other visible items. A stitched pen loop ensures you always have your favorite pen ready
  • High-quality & Easy to Clean: Crafted from high-quality PU leather with heavy-duty stitching, this server book is built to last. It resists tears, scratches, and its waterproof surface makes cleaning easy with just a damp cloth or a non-chlorine sanitizer
  • Perfect Fit for Your Apron: Measuring 5” x 8”, this compact organizer is slightly smaller than other models, making it ideal for bending or sitting while carrying in your server apron. It holds everything a waitress needs—a place for everything
  • What's Included: This server organizer comes with multiple open and zippered pockets to store money, receipts, tips, etc. Clear sleeves are perfect for keeping menus or special lists while serving. Available in a variety of colors, allowing you to express yourself even when in uniform

Run a basic DNS zone test

Local installation

  1. Install Zonemaster-LDNS, Zonemaster-Engine, and Zonemaster-CLI in that order, following the project documentation.
  2. Run zonemaster-cli example.com, replacing example.com with the zone you want to test.

Docker

  1. Run docker run -t --rm zonemaster/cli example.com, substituting your domain name.
  2. If your machine has no IPv6 connectivity or IPv6 is not enabled in the Docker daemon, add --no-ipv6 to avoid misleading errors associated with unavailable IPv6.

The CLI prints findings while its test cases run. The guide provides the command forms above and options for tailoring a run. Zonemaster-CLI documentation

Interpret severity levels and output carefully

Messages carry severity labels including CRITICAL, ERROR, WARNING, NOTICE, and INFO. By default, the CLI reports NOTICE and higher. To include INFO messages, lower the threshold with --level=INFO. A WARNING or NOTICE is not automatically evidence of an outage: read the individual message and its test context. For example, the guide’s sample output contains warnings about DNSKEY algorithm or key size and a notice about an SOA refresh value; those messages should be evaluated on their stated details rather than generalized into a blanket verdict.

  • Use --show-testcase to associate findings with the test case that emitted them.
  • Use the documented locale options to change translated messages.
  • Plain text is the default output; raw and JSON output options are also available.

For focused diagnostics, use --test to select a named test case or test level, or ask the CLI to list available tests. The guide does not enumerate every test family or define every test’s semantics, so consult the current test-case specifications and manual page when a particular result needs interpretation. Zonemaster-CLI documentation

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check proposed delegation data before changing parent records

If you are preparing to change parent NS, glue, or DS records, an undelegated test lets you supply the parent data planned for the child zone and assess it before updating the live parent delegation. The guide’s option formats are:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Repeat --ns for each nameserver, using name/address form.
  • Repeat --ds for each DS record, using keytag, algorithm, digest-type, and digest form.

Use the exact options and syntax shown in the current CLI guide for the intended undelegated test. This checks the proposed inputs through Zonemaster’s tests; it does not make the parent change or guarantee that every operational concern has been covered. Zonemaster-CLI documentation

Use custom root hints when needed

The --hints option accepts a custom root hints file. With Docker, mount the file into the container and pass the path as visible inside that container, rather than assuming a host path is automatically accessible. Refer to the CLI guide for the invocation details. Zonemaster-CLI documentation

Check the release information

The Zonemaster project release page identifies v8.0.2 as the latest CLI release in its displayed listing and says it is part of Zonemaster v2026.1 and v2026.1.1. The captured release entry shows “29 Jun” without a year, so that date should not be treated as a confirmed year-specific release date. Check the project page for current release information before relying on a version number. Zonemaster-CLI releases

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.