如何将自有Bind9 DNS服务器与已购全球域名绑定(注册商仅支持自定义域名服务器场景)
Alright, let's walk through this step by step—you're already halfway there with your domain and a public IP Bind9 server. Here's exactly what you need to do:
Step 1: Configure Your Bind9 Server as the Authoritative DNS for Your Domain
First, you need to set up Bind9 to host the authoritative zone file for your domain. This tells your server how to respond to DNS queries for your domain.
Create a zone file for your domain
Navigate to your Bind9 zones directory (typically/etc/bind/zones/) and create a file nameddb.yourdomain.com(replaceyourdomain.comwith your actual domain). Paste this template, updating the values to match your setup:$TTL 3600 @ IN SOA ns1.yourdomain.com. admin.yourdomain.com. ( 2024052001 ; Serial (increment this every time you edit the file) 3600 ; Refresh (how often secondary DNS checks for updates) 1800 ; Retry (how long to wait before retrying a failed refresh) 604800 ; Expire (how long secondary DNS keeps records if unreachable) 3600 ) ; Negative Cache TTL (how long to cache "record not found" responses) ; Define your domain's nameservers @ IN NS ns1.yourdomain.com. @ IN NS ns2.yourdomain.com. ; Optional but recommended (most registrars require 2+ NS records) ; Map your nameservers to your public IP ns1 IN A 123.45.67.89 ; Replace with your Bind9 server's public IP ns2 IN A 123.45.67.89 ; Use the same IP if you only have one server ; Add records for your services (example: web server) @ IN A 123.45.67.89 ; Root domain points to your service IP www IN A 123.45.67.89 ; www subdomain points to your service IPLink the zone file to Bind9's configuration
Open/etc/bind/named.conf.localand add this block at the bottom:zone "yourdomain.com" { type master; file "/etc/bind/zones/db.yourdomain.com"; };Validate and restart Bind9
Run these commands to check for configuration errors:named-checkconf # Checks main Bind9 config named-checkzone yourdomain.com /etc/bind/zones/db.yourdomain.com # Checks your zone fileIf no errors pop up, restart the Bind9 service:
sudo systemctl restart bind9
Step 2: Set Up Custom Nameservers + Glue Records at Your Registrar
Since your registrar only lets you add custom nameservers (not direct IPs), you need to use glue records—these tell global DNS servers the IP address of your custom nameservers before they can query your Bind9 server. Here's how:
Log into your domain registrar's dashboard
Find the section for managing your domain's nameservers (usually labeled "Nameservers", "Custom DNS", or "Domain Settings").Add your custom nameservers
Enter two nameservers (most registrars require at least two):ns1.yourdomain.comns2.yourdomain.com
Configure glue records
Most registrars will prompt you to enter the IP address associated with each nameserver when you add them. Paste your Bind9 server's public IP for bothns1andns2(even if they point to the same server). This is the critical glue record setup—without it, global DNS won't know where to find your Bind9 server.Save and propagate changes
Save your settings, then wait for DNS propagation. This can take anywhere from 1 hour to 24 hours, depending on the TTL values set in your zone file.
Step 3: Verify Everything Works
Once propagation is complete, test your setup with these commands:
- Check if your domain points to your custom nameservers:
dig yourdomain.com NS - Check if your service records resolve correctly:
dig yourdomain.com A - You can also test from a different network (like your phone's cellular data) to confirm global accessibility.
Key Notes to Remember
- Open port 53: Make sure your Bind9 server's firewall and router allow incoming traffic on UDP and TCP port 53 (DNS uses both protocols).
- Static IP: Use a static public IP for your Bind9 server—if you have a dynamic IP, you'll need to set up DDNS to automatically update the IP in your zone file.
- Serial number: Always increment the serial number in your zone file when you make changes—this tells secondary DNS servers to pull the latest records.
内容的提问来源于stack exchange,提问作者Alan Wake

