您现在访问的是微软AZURE全球版技术文档网站,若需要访问由世纪互联运营的MICROSOFT AZURE中国区技术文档网站,请访问 https://docs.azure.cn.

什么是 Azure DNS?What is Azure DNS?

Azure DNS 是 DNS 域的托管服务,它使用 Microsoft Azure 基础结构提供名称解析。Azure DNS is a hosting service for DNS domains that provides name resolution by using Microsoft Azure infrastructure. 通过在 Azure 中托管域,可以使用与其他 Azure 服务相同的凭据、API、工具和计费来管理 DNS 记录。By hosting your domains in Azure, you can manage your DNS records by using the same credentials, APIs, tools, and billing as your other Azure services.

不能使用 Azure DNS 来购买域名。You can't use Azure DNS to buy a domain name. 对于年度费用,可以使用应用服务域或第三方域名注册机构购买域名。For an annual fee, you can buy a domain name by using App Service domains or a third-party domain name registrar. 然后,可以将域托管在 Azure DNS 中来管理记录。Your domains then can be hosted in Azure DNS for record management. 有关详细信息,请参阅 向 Azure DNS 委派域For more information, see Delegate a domain to Azure DNS.

Azure DNS 附带了以下功能。The following features are included with Azure DNS.

可靠性和性能Reliability and performance

Azure DNS 中的 DNS 域托管在 DNS 名称服务器的 Azure 全球网络上。DNS domains in Azure DNS are hosted on Azure's global network of DNS name servers. Azure DNS 使用任意广播网络。Azure DNS uses anycast networking. 每个 DNS 查询由最近的可用 DNS 服务器来应答,为你的域提供快速性能和高可用性。Each DNS query is answered by the closest available DNS server to provide fast performance and high availability for your domain.

安全Security

Azure DNS 基于 Azure 资源管理器,后者提供以下功能:Azure DNS is based on Azure Resource Manager, which provides features such as:

  • 基于角色的访问控制:控制谁有权访问针对组织的特定操作。Role-based access control to control who has access to specific actions for your organization.

  • 活动日志:监视你的组织中的用户对资源进行了怎样的修改,或者在进行故障排除时查找错误。Activity logs to monitor how a user in your organization modified a resource or to find an error when troubleshooting.

  • 资源锁定:锁定订阅、资源组或资源。Resource locking to lock a subscription, resource group, or resource. 锁定可以防止组织中的其他用户意外删除或修改重要资源。Locking prevents other users in your organization from accidentally deleting or modifying critical resources.

有关详细信息,请参阅如何保护 DNS 区域和记录For more information, see How to protect DNS zones and records.

DNSSECDNSSEC

Azure DNS 当前不支持 DNSSEC。Azure DNS does not currently support DNSSEC. 在大多数情况下,可以通过在应用程序中始终使用 HTTPS/TLS 来减少对 DNSSEC 的需求。In most cases, you can reduce the need for DNSSEC by consistently using HTTPS/TLS in your applications. 如果 DNSSEC 是 DNS 区域的关键要求,则可以使用第三方 DNS 托管提供者托管这些区域。If DNSSEC is a critical requirement for your DNS zones, you can host these zones with third party DNS hosting providers.

易于使用Ease of use

Azure DNS 可以管理 Azure 服务的 DNS 记录,还可以为外部资源提供 DNS。Azure DNS can manage DNS records for your Azure services and provide DNS for your external resources as well. Azure DNS 集成在 Azure 门户中,与其他 Azure 服务使用相同的凭据、支持合同和计费功能。Azure DNS is integrated in the Azure portal and uses the same credentials, support contract, and billing as your other Azure services.

DNS 基于在 Azure 中托管的 DNS 区域数和接收的 DNS 查询数进行计费。DNS billing is based on the number of DNS zones hosted in Azure and on the number of DNS queries received. 若要深入了解定价,请参阅 Azure DNS 定价To learn more about pricing, see Azure DNS pricing.

可以通过 Azure 门户、Azure PowerShell cmdlet 和跨平台 Azure CLI 对域和记录进行管理。Your domains and records can be managed by using the Azure portal, Azure PowerShell cmdlets, and the cross-platform Azure CLI. 需要自动 DNS 管理的应用程序可通过 REST API 和 SDK 与服务进行集成。Applications that require automated DNS management can integrate with the service by using the REST API and SDKs.

具有专用域的可自定义虚拟网络Customizable virtual networks with private domains

Azure DNS 还支持 DNS 专用域。Azure DNS also supports private DNS domains. 此功能允许在专用虚拟网络中使用自定义域名而不使用当前可用的由 Azure 提供的名称。This feature allows you to use your own custom domain names in your private virtual networks rather than the Azure-provided names available today.

有关详细信息,请参阅在专用域中使用 Azure DNSFor more information, see Use Azure DNS for private domains.

别名记录Alias records

Azure DNS 支持别名记录集。Azure DNS supports alias record sets. 可以使用别名记录集来引用 Azure 资源,例如 Azure 公共 IP 地址、Azure 流量管理器配置文件或 Azure 内容分发网络 (CDN) 终结点。You can use an alias record set to refer to an Azure resource, such as an Azure public IP address, an Azure Traffic Manager profile, or an Azure Content Delivery Network (CDN) endpoint. 如果基础资源的 IP 地址发生更改,别名记录集将在 DNS 解析过程中无缝更新。If the IP address of the underlying resource changes, the alias record set seamlessly updates itself during DNS resolution. 别名记录集指向服务实例,而服务实例与 IP 地址相关联。The alias record set points to the service instance, and the service instance is associated with an IP address.

另外,现在可以使用别名记录将顶点或裸域指向流量管理器配置文件或 CDN 终结点。Also, you can now point your apex or naked domain to a Traffic Manager profile or CDN endpoint using an alias record. 例如 contoso.com。An example is contoso.com.

有关详细信息,请参阅 Azure DNS 别名记录概述For more information, see Overview of Azure DNS alias records.

后续步骤Next steps