---
title: "Creating Authoritative Subzones"
canonical: "https://docs.infoblox.com/space/BloxOneDDI/186681692/Creating%20Authoritative%20Subzones"
format: markdown
---
<span style="color: #000000">After creating a zone, you can add more zones at the same level, or add subordinate zones (subzones). The subzones can be authoritative. </span>

<span style="color: #000000">The distinction between domains and zones is that domains provide a logical structure to the DNS name space while zones provide an administrative structure. The difference between domains and subdomains, and zones and subzones is that the terms subdomains and subzones reference their relationship to a parent domain or zone. With the exception of the root domain and root zone, all domains are subdomains and all zones are subzones.</span>

<span style="color: #000000">You can organize a domain based on logical divisions such as </span><span style="color: #000000">**type**</span><span style="color: #000000"> (.com, .gov, .edu; or sales, eng, sup) or </span><span style="color: #000000">**location**</span><span style="color: #000000"> (.uk, .jp, .us; or hq, east, west). The figure below shows one way to organize the external (public) namespace and the internal (private) namespace for a corporation with the domain name </span><span style="color: #000000">[example.com](http://example.com)</span><span style="color: #000000">. The external namespace follows standard DNS conventions. Internally, you create an individual subdomain and corresponding subzone for each department. </span>


> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">Throughout this documentation, the trailing period (“.”) indicating the root zone is not shown, although its presence is assumed.</span>

<span style="color: #000000">The procedure for adding a subzone is the same as that used to add an authoritative zone. The only difference is that you specify the subzone name in the </span><span style="color: #000000">**Name**</span><span style="color: #000000"> field. For information about adding authoritative zones, see </span><span style="color: #000000">*[Creating a Primary Zone](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186681644)*</span><span style="color: #000000">.</span>

> ❌ Creating a CNAME record with the same name as a subzone (delegated zone) or vice-versa is not recommended and generally not allowed in DNS configurations.

<span style="color: #000000">To create an authoritative subzone, complete the following:</span>

1. From the Infoblox Portal, click **Network** > <span style="color: #000000">**DNS **</span>> <span style="color: #000000">** Zones**</span>.
2. <span style="color: #000000">Create a DNS view or click an existing DNS view. For more information about creating a DNS view, see </span><span style="color: #000000">*[Configuring DNS Views](https://docs.infoblox.com/display/ddiadminguidensdraft/Configuring+DNS+Views)*</span><span style="color: #000000">.</span>
3. <span style="color: #000000">Click the zone where you want to add a subzone. </span>
4. <span style="color: #000000">Click </span><span style="color: #000000">**Create **</span><span style="color: #000000">></span><span style="color: #000000">** Zone **</span><span style="color: #000000">and choose </span><span style="color: #000000">**Primary Zone **</span><span style="color: #000000">from the drop-down list.</span>
5. <span style="color: #000000">On the </span><span style="color: #000000">*Create Primary Zone*</span><span style="color: #000000"> page, select the zone to which you want to add a subzone.</span>
6. <span style="color: #000000">Configure the following to create a subzone:</span>
  - <span style="color: #000000">**Name**</span><span style="color: #000000">: Enter the name of the subzone and select the name of the zone for which you want to create the subzone.</span>
  - <span style="color: #000000">**Description**</span><span style="color: #000000">: Optionally, enter additional information about the subzone.</span>
  - <span style="color: #000000">**Disable for DNS Protocol**</span><span style="color: #000000">: Select this option to temporarily disable the subzone. For information, see </span><span style="color: #000000">*[Enabling and Disabling Zones.](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186617648)*</span>
  - <span style="color: #000000">**DNS SERVERS**</span><span style="color: #000000">: You can associate DNS servers with the subzone. see </span><span style="color: #000000">*[Creating a Secondary Zone](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186681610)*</span><span style="color: #000000">. For information on specifying authoritative DNS server groups, see </span><span style="color: #000000">*[Configuring DNS Server Groups](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186746079)*</span><span style="color: #000000">. To edit an existing primary or a secondary server or a DNS server group, select the respective row and click the </span><span style="color: #000000">**Edit**</span><span style="color: #000000"> button. You can select a row and click the </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> button to delete a row.</span>
  - <span style="color: #000000">**Tags**</span><span style="color: #000000">: Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to associate keys with the reverse-mapping zone and specify the following details:</span>
  - 
    - <span style="color: #000000">**KEY**</span><span style="color: #000000">: Enter a meaningful name for the key, such as a location or a department.  </span>
    - <span style="color: #000000">**VALUE**</span><span style="color: #000000">: Enter a value for the key.   </span>  
<span style="color: #000000">To remove a tag, select the respective check box and click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to delete the associated tag. For information about tags, see </span><u><span style="color: #000000">*[Managing Tags](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186745865)*</span></u><span style="color: #000000">.</span>
7. <span style="color: #000000">Configure the Zone Settings Defaults. The Zone Settings Defaults are inherited from Global DNS Properties. For more information, see </span><u><span style="color: #000000">*[Configuring Global DNS Properties](https://docs.infoblox.com/display/ddiadminguidensdraft/Configuring+Global+DNS+Properties)*</span></u><span style="color: #000000">. Alternatively, toggle </span><span style="color: #000000">**Inherit**</span><span style="color: #000000"> to </span><span style="color: #000000">**Off**</span><span style="color: #000000"> and configure the values for each of the following:</span>
  - <span style="color: #000000">**Refresh**</span><span style="color: #000000">: Specify the value and choose Hours,  Minutes, or Seconds from the drop-down list.</span>
  - <span style="color: #000000">**Retry**</span><span style="color: #000000">: Specify the value and choose Hours, Minutes, or Seconds from the drop-down list.</span>
  - <span style="color: #000000">**Expire**</span><span style="color: #000000">: Specify the value and choose Days, Hours, Minutes, or Seconds from the drop-down list.</span>
  - <span style="color: #000000">**Default TTL**</span><span style="color: #000000">: Specify the value and choose Hours, Minutes, or Seconds from the drop-down list.</span>
  - <span style="color: #000000">**Negative-caching TTL**</span><span style="color: #000000">: Specify the value and choose Minutes or Seconds from the drop-down list.</span>
  - <span style="color: #000000">**EMAIL ADDRESS (FOR SOA RNAME FIELD)**</span><span style="color: #000000">: Specify an email address for the SOA RNAME FIELD.</span>
  - <span style="color: #000000">Use default forwarders to resolve queries for delegated zones, select the check box to use the default forwarders for delegated zones.</span>
8. <span style="color: #000000">Configure the Queries. The queries are inherited from Global DNS Properties. For more information, see </span><u><span style="color: #000000">*[Configuring Global DNS Properties](https://docs.infoblox.com/display/ddiadminguidensdraft/Configuring+Global+DNS+Properties)*</span></u><span style="color: #000000">. Alternatively, toggle </span><span style="color: #000000">**Inherit**</span><span style="color: #000000"> to </span><span style="color: #000000">**Off**</span><span style="color: #000000"> and configure the values in the </span><span style="color: #000000">**ALLOW QUERIES FROM**</span><span style="color: #000000"> section. Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Choose one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:   </span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Choose this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the client from which the query originates. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Choose this option to add a network to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Choose this option to add a named ACL that you want to use. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs are displayed. If you have only one named ACL, the application automatically displays the named ACL. When you select this, the application replies to DNS queries from clients matching the ACL. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the selected named ACL.</span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Choose this option to allow or deny queries from any IP addresses or networks. The application replies to queries from all clients. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
9. <span style="color: #000000">Configure the Zone transfers. The queries are inherited from Global DNS Properties. For more information, see </span><u><span style="color: #000000">*[Configuring Global DNS Properties](https://docs.infoblox.com/display/ddiadminguidensdraft/Configuring+Global+DNS+Properties)*</span></u><span style="color: #000000">. Alternatively, toggle </span><span style="color: #000000">**Inherit**</span><span style="color: #000000"> to </span><span style="color: #000000">**Off**</span><span style="color: #000000"> and configure the values in the </span><span style="color: #000000">**ACCEPT ZONE TRANSFER REQUESTS FROM**</span><span style="color: #000000"> section. Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Choose one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:   </span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Choose this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the remote server. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays Allow by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Choose this option to add an IPv4 network address to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Choose this option to add a named ACL. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs are displayed. If you have only one named ACL, it is displayed automatically. When you select this, the application allows servers permission to send and receive DNS zone transfer data. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the selected named ACL.</span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Choose this option to allow or deny the application to send zone transfers to any IP address or network. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
10. <span style="color: #000000">Configure dynamic updates. The dynamic updates are inherited from Global DNS Properties. For more information, see </span><u><span style="color: #000000">*[Configuring Global DNS Properties](https://docs.infoblox.com/display/ddiadminguidensdraft/Configuring+Global+DNS+Properties)*</span></u><span style="color: #000000">. Alternatively, toggle </span><span style="color: #000000">**Inherit**</span><span style="color: #000000"> to </span><span style="color: #000000">**Off**</span><span style="color: #000000"> and configure the values in the </span><span style="color: #000000">**ALLOW DYNAMIC UPDATES**</span><span style="color: #000000"> section. Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Choose one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list: </span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Choose this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the remote server. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays Allow by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Choose this option to add an IPv4 network address to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Choose this option to add a named ACL. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs are displayed. If you have only one named ACL, it is displayed automatically. When you select this, the application allows servers permission to send and receive DNS zone transfer data. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the selected named ACL.</span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Choose this option to allow or deny the application to send zone transfers to any IP address or network. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
11. <span style="color: #000000">Click </span><span style="color: #000000">**Save & Close**</span><span style="color: #000000"> to save.</span>

<span style="color: #000000">To modify or delete a subzone, click the respective zone name with which the subzone is associated. When you click the zone name, the list of subzones associated with it are listed. Click </span><span style="color: #1d1c1d">☰</span><span style="color: #000000"> and select </span><span style="color: #000000">**Edit**</span><span style="color: #000000"> from the list to modify the details or </span><span style="color: #000000">**Delete**</span><span style="color: #000000"> to delete the subzone. You can also select the check box and click the </span><span style="color: #000000">**Edit**</span><span style="color: #000000"> button to modify or</span><span style="color: #000000">** **</span><span style="color: #000000">click the</span><span style="color: #000000">** Delete**</span><span style="color: #000000"> button to delete the subzone.</span>