Agent skill

DNS Management

by sickn33 in sickn33/agentic-awesome-skills

Configure DNS zones and records. An agent skill from sickn33/agentic-awesome-skills.

MITAuto-check passedDevOps & Cloud

Install DNS Management

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill dns-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills dns-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dns-management .claude/skills/dns-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dns-management
GitHub stars
47k
Used in
2 other repos
Token cost
~2.7k tokens
SKILL.md length
430 words
Files
1
Skills in repo
1,493
Repo updated
First seen
Licence
MIT

At a glance

Configure DNS zones and records. An agent skill from sickn33/agentic-awesome-skills.

  • Setting up DNS infrastructure
  • SKILL.md covers When to Use, Prerequisites, DNS Record Types Reference and AWS Route 53, plus 8 more sections
  • Calls aws, curl and jq; reaches api.cloudflare.com; needs CF_API_TOKEN
  • Tasks that involve Cloud networking

What it does

DNS Management is an agent skill from sickn33/agentic-awesome-skills. Configure DNS zones and records. Manage Route53, Cloud DNS, and self-hosted DNS. Use when setting up DNS infrastructure.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

It sits in DevOps & Cloud, covering Cloud networking. It works with Cloudflare and Terraform. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Setting up DNS infrastructure
  • Tasks that involve Cloud networking

Example prompts

  • “/dns-management”

Requirements

  • A credential in CF_API_TOKEN
  • Compatibility (from SKILL.md): Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

What it can do on your machine

Read from SKILL.md and the folder at commit 680176d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws
    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CF_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

DNS Management loads about 2.7k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 430 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 680176d, republished under its MIT licence (© sickn33). 430 words, ~2,716 tokens.

Download SKILL.mdSave it as .claude/skills/dns-management/SKILL.md (or your agent's skills folder).
name
dns-management
description
Configure DNS zones and records. Manage Route53, Cloud DNS, and self-hosted DNS. Use when setting up DNS infrastructure.
compatibility
Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.
category
devops
risk
critical
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
metadata.author
devops-skills
metadata.version
1.0

DNS Management

Configure and manage DNS zones, records, and resolution for production infrastructure.

When to Use

  • Setting up domains for web applications, APIs, and email.
  • Migrating DNS providers or consolidating zones.
  • Configuring DNS for CDN, load balancers, and cloud services.
  • Troubleshooting resolution failures, propagation delays, or misconfigurations.
  • Implementing DNSSEC, SPF, DKIM, and DMARC for email security.

Prerequisites

  • Domain registered with a registrar (Namecheap, Route53, Google Domains, Cloudflare).
  • Access to DNS provider dashboard or API.
  • AWS CLI configured (for Route53 examples).
  • dig and nslookup available locally (included in most OS installs).

DNS Record Types Reference

TypePurposeExample Value
AIPv4 address93.184.216.34
AAAAIPv6 address2606:2800:220:1:248:1893:25c8:1946
CNAMEAlias to another domainwww.example.com -> example.com
MXMail server with priority10 mail.example.com
TXTArbitrary text (SPF, DKIM, verification)v=spf1 include:_spf.google.com ~all
NSAuthoritative name serversns1.example.com
SRVService location (host, port, priority)10 5 5060 sip.example.com
CAACertificate Authority Authorization0 issue "letsencrypt.org"
PTRReverse DNS lookup34.216.184.93.in-addr.arpa

AWS Route 53

Hosted Zone Management
bash
# Create a hosted zone
aws route53 create-hosted-zone \
  --name example.com \
  --caller-reference "$(date +%s)"

# List hosted zones
aws route53 list-hosted-zones

# Get name servers for a zone (update at your registrar)
aws route53 get-hosted-zone --id Z1234567890ABC \
  --query 'DelegationSet.NameServers'
Create and Manage Records
bash
# Create an A record
aws route53 change-resource-record-sets \
  --hosted-zone-id Z1234567890ABC \
  --change-batch '{
    "Changes": [{
      "Action": "CREATE",
      "ResourceRecordSet": {
        "Name": "app.example.com",
        "Type": "A",
        "TTL": 300,
        "ResourceRecords": [{"Value": "93.184.216.34"}]
      }
    }]
  }'

# Create a CNAME record
aws route53 change-resource-record-sets \
  --hosted-zone-id Z1234567890ABC \
  --change-batch '{
    "Changes": [{
      "Action": "CREATE",
      "ResourceRecordSet": {
        "Name": "www.example.com",
        "Type": "CNAME",
        "TTL": 300,
        "ResourceRecords": [{"Value": "example.com"}]
      }
    }]
  }'

# Create an alias record (no TTL, Route53-specific)
aws route53 change-resource-record-sets \
  --hosted-zone-id Z1234567890ABC \
  --change-batch '{
    "Changes": [{
      "Action": "CREATE",
      "ResourceRecordSet": {
        "Name": "example.com",
        "Type": "A",
        "AliasTarget": {
          "HostedZoneId": "Z2FDTNDATAQYW2",
          "DNSName": "d1234567890.cloudfront.net",
          "EvaluateTargetHealth": false
        }
      }
    }]
  }'

# List records in a zone
aws route53 list-resource-record-sets --hosted-zone-id Z1234567890ABC

# Delete a record (Action: DELETE with exact match)
aws route53 change-resource-record-sets \
  --hosted-zone-id Z1234567890ABC \
  --change-batch '{
    "Changes": [{
      "Action": "DELETE",
      "ResourceRecordSet": {
        "Name": "old.example.com",
        "Type": "A",
        "TTL": 300,
        "ResourceRecords": [{"Value": "1.2.3.4"}]
      }
    }]
  }'
Route 53 Health Checks
bash
# Create a health check
aws route53 create-health-check --caller-reference "$(date +%s)" \
  --health-check-config '{
    "IPAddress": "93.184.216.34",
    "Port": 443,
    "Type": "HTTPS",
    "ResourcePath": "/health",
    "RequestInterval": 30,
    "FailureThreshold": 3
  }'

Cloudflare DNS

Manage Records via API
bash
# Get zone ID
ZONE_ID=$(curl -s "https://api.cloudflare.com/client/v4/zones?name=example.com" \
  -H "Authorization: Bearer $CF_API_TOKEN" | jq -r '.result[0].id')

# Create an A record (proxied through Cloudflare)
curl -X POST "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dns_records" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"type":"A","name":"app","content":"93.184.216.34","proxied":true,"ttl":1}'

# Create a CNAME record (DNS only, not proxied)
curl -X POST "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dns_records" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -d '{"type":"CNAME","name":"docs","content":"docs.readthedocs.io","proxied":false,"ttl":3600}'

# List all records
curl -s "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dns_records" \
  -H "Authorization: Bearer $CF_API_TOKEN" | jq '.result[] | {name, type, content, proxied}'

# Delete a record
curl -X DELETE "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dns_records/$RECORD_ID" \
  -H "Authorization: Bearer $CF_API_TOKEN"

Terraform DNS Management

Route 53 with Terraform
hcl
# dns.tf
resource "aws_route53_zone" "main" {
  name = "example.com"
}

resource "aws_route53_record" "app" {
  zone_id = aws_route53_zone.main.zone_id
  name    = "app.example.com"
  type    = "A"
  ttl     = 300
  records = ["93.184.216.34"]
}

resource "aws_route53_record" "www" {
  zone_id = aws_route53_zone.main.zone_id
  name    = "www.example.com"
  type    = "CNAME"
  ttl     = 300
  records = ["example.com"]
}

# Alias record for CloudFront
resource "aws_route53_record" "cdn" {
  zone_id = aws_route53_zone.main.zone_id
  name    = "example.com"
  type    = "A"

  alias {
    name                   = aws_cloudfront_distribution.main.domain_name
    zone_id                = aws_cloudfront_distribution.main.hosted_zone_id
    evaluate_target_health = false
  }
}

# Email records
resource "aws_route53_record" "mx" {
  zone_id = aws_route53_zone.main.zone_id
  name    = "example.com"
  type    = "MX"
  ttl     = 3600
  records = [
    "1 aspmx.l.google.com",
    "5 alt1.aspmx.l.google.com",
    "5 alt2.aspmx.l.google.com",
  ]
}

resource "aws_route53_record" "spf" {
  zone_id = aws_route53_zone.main.zone_id
  name    = "example.com"
  type    = "TXT"
  ttl     = 3600
  records = ["v=spf1 include:_spf.google.com ~all"]
}

resource "aws_route53_record" "dmarc" {
  zone_id = aws_route53_zone.main.zone_id
  name    = "_dmarc.example.com"
  type    = "TXT"
  ttl     = 3600
  records = ["v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com; pct=100"]
}
Cloudflare with Terraform
hcl
resource "cloudflare_record" "app" {
  zone_id = var.cloudflare_zone_id
  name    = "app"
  content = "93.184.216.34"
  type    = "A"
  proxied = true
}

resource "cloudflare_record" "mail" {
  zone_id  = var.cloudflare_zone_id
  name     = "@"
  content  = "aspmx.l.google.com"
  type     = "MX"
  priority = 1
}

DNS Troubleshooting Commands

dig
bash
# Query A record
dig app.example.com A +short

# Query from a specific DNS server
dig @8.8.8.8 app.example.com A

# Show full answer with TTL
dig app.example.com A +noall +answer

# Query MX records
dig example.com MX +short

# Trace the full resolution path
dig app.example.com +trace

# Check DNSSEC validation
dig example.com +dnssec +short

# Query TXT records (SPF, DKIM)
dig example.com TXT +short
dig default._domainkey.example.com TXT +short
nslookup
bash
# Basic lookup
nslookup app.example.com

# Specify DNS server
nslookup app.example.com 8.8.8.8

# Query specific record type
nslookup -type=MX example.com
nslookup -type=TXT example.com
Check DNS Propagation
bash
# Query multiple public resolvers
for dns in 8.8.8.8 1.1.1.1 9.9.9.9 208.67.222.222; do
  echo "=== $dns ==="
  dig @$dns app.example.com A +short
done

Email Security Records

bash
# SPF — authorize sending servers
# TXT record on example.com
"v=spf1 include:_spf.google.com include:sendgrid.net -all"

# DKIM — email signing verification
# TXT record on google._domainkey.example.com
# (value provided by your email provider)

# DMARC — policy for failed SPF/DKIM
# TXT record on _dmarc.example.com
"v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com; pct=100"

TTL Strategies

ScenarioRecommended TTLRationale
Stable production records3600-86400 (1h-24h)Reduce DNS queries, faster resolution
Pre-migration warmup60-300 (1-5 min)Lower TTL days before migration
During migration/failover60Fast propagation of changes
Post-migration cooldownGradually increase to 3600+Return to normal after confirming stability
Load-balanced records60-300Allow health-check-driven failover
Show full SKILL.md (182 more words)Show less

Troubleshooting

SymptomCauseFix
DNS changes not visibleTTL not expired on recursive resolversWait for old TTL to expire; lower TTL before next change
SERVFAIL responseDNSSEC validation failure or broken delegationCheck NS records at registrar; verify DNSSEC signatures
NXDOMAIN for valid recordWrong hosted zone or missing recordVerify record exists with dig @<authoritative-ns> domain
CNAME at zone apex returns errorCNAME not allowed at zone apex per RFCUse ALIAS (Route53) or proxied A record (Cloudflare)
Email going to spamMissing or broken SPF/DKIM/DMARCVerify TXT records with dig example.com TXT; test at mail-tester.com
Slow resolutionRecursive resolver far from authoritative NSUse Anycast DNS providers (Cloudflare, Route53)
Inconsistent results across resolversPartial propagation or cache poisoningQuery authoritative NS directly; check for conflicting records
  • cdn-setup (cdn-setup) - CDN CNAME and alias record configuration
  • load-balancing (load-balancing) - DNS-based load balancing and health checks
  • cloudflare-zero-trust (cloudflare-zero-trust) - Tunnel DNS routing
  • reverse-proxy (reverse-proxy) - Connecting domains to backend services

Limitations

  • Infrastructure commands can disrupt services: confirm target host/scope and have backups/snapshots before mutating state.
  • Docs-only import: upstream scripts and templates not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/dns-management of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 680176d

Used in 2 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

DNS Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

DNS Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
DNS Management this skillsickn33/agentic-awesome-skills47k2 repos~2.7kAutomated safety check: PassMIT
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Cloudflaredmmulroy/cloudflare-skill727—~1.6kAutomated safety check: PassMIT
Terraform Azurerm Set Diff Analyzergithub/awesome-copilot40k1 repos~547Automated safety check: PassMIT
Troubleshoot Platformaws-samples/appmod-blueprints115—~2kAutomated safety check: PassMIT-0
Ocioracle/skills876—~2.4kAutomated safety check: PassUPL-1.0

Similar skills

  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Cloudflare

    dmmulroy/cloudflare-skill

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…

    727 GitHub stars~1.6k tokensUpdated 8 mo ago
    DevOps & CloudAuto-check passed
  • Official

    Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes.

    40k GitHub starsUsed in 1 repo~547 tokens
    DevOps & CloudAuto-check passed
  • Troubleshoot Platform

    aws-samples/appmod-blueprints

    Official

    Systematic troubleshooting for the PEEKS workshop platform — EKS clusters, Terraform state, ingress, load balancers, MCP tool failures, YAML validation.

    115 GitHub stars~2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Oci

    oracle/skills

    Official

    Oracle Cloud Infrastructure guidance for designing, operating, and troubleshooting OCI services, including OCI Kubernetes Engine (OKE), OCI Internet of Things Platform, OCI Functions deployment and…

    876 GitHub stars~2.4k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Managing DNS

    ancoleman/ai-design-components

    Manage DNS records, TTL strategies, and DNS-as-code automation for infrastructure.

    526 GitHub stars~3.6k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check: notes

More from sickn33/agentic-awesome-skills

All 1,493 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about DNS Management

What does DNS Management do?

Configure DNS zones and records. An agent skill from sickn33/agentic-awesome-skills. DNS Management is an agent skill from sickn33/agentic-awesome-skills. Configure DNS zones and records.

When should I use DNS Management?

DNS Management fits situations like: setting up DNS infrastructure; tasks that involve Cloud networking.

How do I install DNS Management in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill dns-management -a claude-code`. Or copy the skill folder (skills/dns-management in sickn33/agentic-awesome-skills) into .claude/skills/dns-management in your project. Claude Code loads it when a task matches its description.

How do I install DNS Management in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill dns-management -a codex`. Or copy the skill folder (skills/dns-management in sickn33/agentic-awesome-skills) into .agents/skills/dns-management in your project. Codex loads it when a task matches its description.

Can I use DNS Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill dns-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dns-management, .gemini/skills/dns-management, .github/skills/dns-management and .opencode/skills/dns-management in your project.

What does DNS Management need to run?

Going by SKILL.md and its folder, DNS Management needs the command-line tools its instructions call (aws, curl and jq) and credentials named CF_API_TOKEN. Our summary lists: A credential in CF_API_TOKEN. Compatibility (from SKILL.md): Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled..

Does DNS Management access the network?

SKILL.md names 1 domain. In commands or code: api.cloudflare.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is DNS Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does DNS Management use?

DNS Management is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does DNS Management use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to DNS Management?

Skills that share tags, products or a category with DNS Management: Cloudflare (hodgef/apiker, 127 stars), Cloudflare (dmmulroy/cloudflare-skill, 727 stars), Terraform Azurerm Set Diff Analyzer (github/awesome-copilot, 40k stars) and Troubleshoot Platform (aws-samples/appmod-blueprints, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains DNS Management?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,379 GitHub stars. The repository holds 1,493 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.