---
title: How to manage DNS with an AI agent
slug: how-to-manage-dns-with-an-ai-agent
type: guide
targetQuery: manage DNS records with an AI agent / add a DNS record from Claude
canonical: https://top-agent-skills.com/guides/how-to-manage-dns-with-an-ai-agent
published: 2026-09-17
updated: 2026-09-17
---

# How to manage DNS with an AI agent

Use hostinger-agent-skills when you want a rollback, and zeabur-agent-skills when you want one command. Hostinger's dns skill manages zone records with snapshots, validation and a reset-to-defaults path, so a bad edit is recoverable. Zeabur's zeabur-domain-dns creates a record in a single CLI call across A, AAAA, CNAME, MX, TXT, SRV, CAA and NS, with TTL, priority and Cloudflare-proxy flags. Both only manage zones hosted by that company — an agent cannot edit DNS for a domain whose nameservers point somewhere neither skill can reach.

## DNS capability by skill

|   | zeabur-agent-skills | hostinger-agent-skills |
| --- | --- | --- |
| Interface | CLI (npx zeabur@latest) | REST API with bearer token |
| Record types | A, AAAA, CNAME, MX, TXT, SRV, CAA, NS | Full zone record set |
| Rollback | No | Zone snapshots, restore and reset to defaults |
| Validation | Per-command | Explicit zone validation before apply |
| Extras | TTL, MX/SRV priority, proxy-through-Cloudflare flag | Delegation, forwarding, verification state |
| Scope | Zeabur-registered domains | Hostinger-hosted zones |

## Step by step

1. **List the zone before you touch it** — npx zeabur@latest domain dns list --domain example.com -i=false. Reading the zone first is how you catch what an agent will not notice afterwards: a record created on the wrong name, or a second A record left beside the one you meant to replace.
2. **Take a snapshot if the zone is live** — Hostinger’s dns skill can snapshot a zone, validate a change before applying it, restore a previous snapshot, and reset to defaults while whitelisting MX and TXT. Zeabur has none of that. If the zone serves production email or a live site, use the one that can put it back.
3. **Write the record** — npx zeabur@latest domain dns create --domain example.com --type A --name @ --content 93.184.216.34 -i=false for the apex; swap --type CNAME --name www for the subdomain. --ttl takes seconds and defaults to automatic, --priority applies to MX and SRV, --proxied routes through Cloudflare.
4. **Verify against a public resolver** — dig +short example.com @1.1.1.1 — querying 1.1.1.1 directly rather than your own resolver, which may serve a cached answer. For a redirect or a certificate, curl -I https://example.com. Do not verify in a browser; it caches and will lie to you.

## The one-command case

Pointing a name at a server is a single call. npx zeabur@latest domain dns create --domain example.com --type A --name @ --content 93.184.216.34 -i=false writes the apex A record; swap --type CNAME --name www --content example.com for the subdomain. --ttl takes seconds and defaults to 1, which means automatic. --priority applies to MX and SRV. --proxied routes the record through Cloudflare.

Listing is npx zeabur@latest domain dns list --domain example.com -i=false, which is the command to run first and again afterwards. Reading the zone back is how you catch the mistake an agent will not notice: a record created on the wrong name, or a second A record left behind next to the one you meant to replace.

## The case for snapshots

DNS is the part of a launch where a small mistake takes the whole site down, and where the feedback loop is slow enough that you may not notice for an hour. Hostinger's dns skill is built around that: it manages records, but it also takes zone snapshots, validates changes, restores a previous snapshot and resets a zone to defaults.

That changes what it is safe to delegate. Editing a live zone by hand through an agent is a reasonable thing to do when a known-good state is one call away, and an unreasonable one when it is not. If the zone serves anything you care about, prefer the skill that can put it back.

## Verify outside the agent

Neither skill can confirm that the change took effect, because propagation is not theirs to observe. Check it yourself with dig +short example.com @1.1.1.1 — querying a public resolver directly rather than your own, which may be serving a cached answer — and for a redirect or certificate, curl -I https://example.com to see the status line.

Browsers are the worst possible verification tool here. They cache DNS, cache redirects aggressively and will happily show you a stale answer long after the record has changed. A dig that returns the right address and a curl that returns the right status are the two signals worth trusting.

## Common questions

**Can an agent edit DNS for a domain registered anywhere?**

No. Each skill reaches its own company's API, so it can only edit zones that company hosts. For a domain whose nameservers point at a third party, the agent can tell you which records to create but cannot create them.

**Which record types are supported?**

Zeabur documents A, AAAA, CNAME, MX, TXT, SRV, CAA and NS. Hostinger manages the full zone record set through its API. Between them that covers everything a normal site launch, mail setup or domain-verification challenge needs.

**How do I undo a bad DNS change an agent made?**

On Hostinger, restore the zone snapshot taken before the edit, or reset the zone to defaults. On Zeabur there is no snapshot, so recovery means listing the zone and re-creating the record you overwrote — which is why listing before and after every change is worth the extra call.

**Does a DNS skill handle SPF, DKIM and DMARC?**

Yes, as TXT records like any other. Hostinger's own examples cover setting up SPF and DKIM for email. The skill writes the record; getting the policy string right is still on you.

**Why does my site still show the old server?**

Almost always caching, not the record. Check with dig +short against a public resolver rather than in a browser, and wait out the TTL that was on the previous record — the new TTL only governs the next change.

## Related

- [How to buy a domain with an AI agent](https://top-agent-skills.com/guides/how-to-buy-a-domain-with-an-ai-agent) — The registration step that comes before any of this.
- [Build, host and launch a website with Skills](https://top-agent-skills.com/guides/launch-a-website-with-ai-agent-skills) — Where DNS sits in the full four-step chain.
- [Deploy a static site to GitHub Pages](https://top-agent-skills.com/guides/deploy-static-site-to-github-pages-with-ai-agent) — The one deploy skill that also configures apex and CNAME records for you.
- [Top DevOps & infrastructure Skills](https://top-agent-skills.com/top-skills-for-devops-infra) — The wider category both DNS-capable skills sit in.

---

_Top Agent Skills. Machine-readable twin of https://top-agent-skills.com/guides/how-to-manage-dns-with-an-ai-agent._
_Catalog as one JSON file (CC BY 4.0): https://top-agent-skills.com/skills.json_
