The domain name is registered at Gandi under the user ieNua8ja.

After the bind-host virtual machine is created, click on Glue record management in the Gandi web interface and set ns1 to the IP, i.e. and wait a few minutes. Click on Update DNS and set the DNS1 server to and click on Add Gandi’s secondary nameserver which should add a new entry in DNS2: it will automatically act as a secondary DNS.

The bind-host virtual machine should be initialized before any other because everything depends on it.


The admin mail is hosted at Gandi and is used as the primary contact for all resources (hosting etc.). In case a password is lost this is the mail receiving the link to reset the password etc.


The zone is managed on a dedicated virtual machine It is generated via the bind playbook.

  • The port udp/53 is open to all but recursion is only allowed for IPs of the VMs
  • An A record is created for all existing VM names
  • A CNAME record is created for all VM names without the -host suffix
  • The SPF TXT record help send mail successfully. and

They can be updated locally by the debian user via nsupdate. Example:

- E - debian@bind-host:~$ nsupdate <<EOF
server localhost
update add 1800 TXT "Updated by nsupdate"