# DNS with `aral`

    aral dns add-zone --name example.uz
    aral dns zones
    aral dns add-record --name www --type A --content 203.0.113.10 example.uz
    aral dns records example.uz
    aral dns update-record --content 203.0.113.11 <record-id>   # name/type immutable
    aral dns delete-record <record-id>
    aral dns delete-zone example.uz

Zones are addressed by NAME everywhere (ids also accepted). After creating a
zone, point the domain's NS records at the nameservers the zone object lists.
Records support proxied mode (Cloudflare-style orange cloud): add
`--mode proxied` to serve through the edge with TLS; `--mode dns_only` is
plain DNS.

## External domains (DNS hosted elsewhere)

A domain whose DNS stays at another provider can still be served through the
edge — TLS, WAF, hidden origin — without moving the zone here:

    aral dns external add shop.example.uz --origin 10.0.0.5:8080 --origin 10.0.0.6:8080
    aral dns external list
    aral dns external verify shop.example.uz
    aral dns external set-origins shop.example.uz --origin 10.0.0.7:8080
    aral dns external rm shop.example.uz

`add` answers with an `instructions` object: publish the `a`/`aaaa` (or the
`cname`) record for the name and the `txt_name`/`txt_value` ownership record at
your provider, then run `verify`. A verify that does not pass fails with the
reason (what the resolver actually answered) so you can compare it with the
instructions; the platform also re-checks on its own every minute for the
first hour and every ten minutes after that, and the domain goes `active` the
moment the records match. `--origin` is repeatable and `set-origins` replaces
the whole set. Domains are addressed by name (ids also accepted). Once active,
a domain that stops pointing at the edge keeps serving for 72 hours and the
organization is notified — restore the record within that window or it stops.
