Almost every zone anyone creates is a primary zone, and on most plans it is the only kind you can create. This page is for the cases where it is not.
Where to see a zone's type
The zones list does not show it. There was a Type column and it has been removed — it read Primary on every row, for almost every account, and spent a column of the table saying so.
Open the zone to see its type. It is the first thing on the line under the domain name:
Primary zone · 4 records · 4 of 250 counted · DNSSEC off
If your account holds more than one type, a Type filter appears above the zones list and narrows it to one of them. On an account where every zone is primary — which is every plan that can only create primary zones — there is nothing to filter between, so the filter is not shown either.
Choosing a type when you add a zone
The Zone type dropdown is in the Add zone dialog, under the domain name.
On the free plan there is no dropdown. Every paid plan — Starter upwards — can create all four types. On the free plan the field is not shown and every zone you create is primary, which is what you want.
Two things follow the dropdown and appear only when they are needed:
- Primary nameserver address — for a secondary or stub zone. The address of the server that holds the real copy.
- Forwarder address — for a forwarder zone. The resolver that queries should be sent to.
The four types
| Type | We hold the records | What it is for |
|---|---|---|
| Primary | Yes — you edit them here | A domain you run. This is the normal one. |
| Secondary | Yes — copied from your server | A domain whose master copy lives somewhere else. |
| Stub | Only the NS records | Knowing which servers are authoritative for a name, without holding it. |
| Forwarder | No | Sending queries for a name to a nominated resolver instead of answering them. |
Primary
You hold the zone, you edit the records here, and our nameservers answer for it. Everything else in this wiki is written about primary zones.
Secondary
The real copy of the zone lives on your server. Ours pull it from the address you give and then answer for it as well, which is how you put a domain behind our nameservers without moving where it is edited.
Edit a secondary zone on your own server, not here. The copy we hold is a replica, replaced by yours on each transfer. The portal does not currently hide the record editor on a secondary zone, so treat what it shows as a view of the copy rather than something to change.
Stub
A stub zone stores nothing but the NS records for a name. It is a pointer that says these servers are authoritative for this, and it is a specialist tool inside a larger DNS estate rather than something a domain needs.
Forwarder
A forwarder zone does not hold records at all. Instead of answering for the name, our nameserver passes the query on to the resolver address you gave it and returns whatever comes back. It is a redirection of responsibility, not a copy of anything.
Setting up a secondary zone
- Zones → Add zone.
- Enter the domain —
example.com. Exactly as it is on your own server. - Set Zone type to
Secondary. - In Primary nameserver address, put the address of the server holding the real zone — an IP address, or a hostname.
- Create zone.
Allow the transfer first, from every address
Every one of our servers pulls the zone from your server directly. The zone is created as a secondary on each of them with your address as its primary — there is no single collector that fetches once and passes it on.
The portal prints the exact list. Choose Secondary in the Add zone dialog and the addresses appear beside the address field, ready to copy into your access list. Use that list rather than one from anywhere else: it is read from the platform's own configuration, so it stays correct if a server is renumbered.
It is five addresses, not four. Four are the public nameservers you delegate to; the fifth is the primary the zone is created on, which is not a public nameserver and appears in no NS record anywhere. It still transfers from you, and an access list built by looking up ns01–ns04 will be missing it.
If your access list is missing any of them, that server holds an empty zone. For the four public ones that means answering as if the domain does not exist, for whichever share of your visitors it happens to be asked. Allow them all before you create the zone, not after.
Our nameservers must be in your NS records
A secondary zone is served exactly as it was transferred, so the NS records your visitors get are the ones in your zone, not ours. We do not add ours to a secondary zone and do not rewrite its SOA — for a primary zone we do both, and that difference is the point of the type.
Add our four public nameservers to your own zone's NS records before you delegate to them — ns01 through ns04.kumodns.com, listed on your dashboard. See Pointing your registrar at KumoDNS.
Those four are the delegation list, and they are not the same as the transfer list above, which has five entries. One is what the world is told; the other is who is allowed to ask you for a copy.
Editing afterwards
Edit on your own server. Your copy is the one that counts, ours is replaced on each transfer, and the portal does not currently hide the record editor on a secondary zone — treat what it shows as a view.
Setting up a forwarder zone
- Zones → Add zone.
- Enter the name the forwarding should apply to —
internal.example.com. - Set Zone type to
Forwarder. - In Forwarder address, put the resolver that should answer — an IP address such as
1.1.1.1, or a hostname. - Create zone.
Queries are forwarded over UDP. There is no setting for that in the portal.
Before you create one
A forwarder zone is an unusual thing to put on a public authoritative nameserver, and it is worth being sure it is what you mean. Our nameservers exist to answer for domains you hold. A forwarder zone makes them relay queries for a name to somebody else's resolver instead, and the answers your visitors get are then whatever that resolver decides to return. If what you actually want is "this subdomain is run by another team's nameservers", that is NS records on the parent zone, not a forwarder zone — see Editing DNS records.
You cannot change it afterwards
This applies to secondary and stub zones as much as to forwarder ones.
The zone type, the primary nameserver address and the forwarder address are all set once, when the zone is created. There is no screen to edit them later, and the record editor does not offer the FWD record type, so the forwarding target cannot be corrected from there either.
Getting one wrong means deleting the zone and creating it again.
Create the replacement from scratch — do not restore it from the recycle bin. A restored zone comes back with its type but without its primary nameserver address or forwarder address, because those are not kept when the zone is deleted. Restoring a forwarder zone therefore gives you a forwarder zone with nothing to forward to. For a primary zone, which is what the recycle bin is really for, nothing is lost.
On the free plan
Nothing is hidden from you by mistake: if you cannot see the Zone type dropdown, you are on the free plan, which creates primary zones only. Every paid plan offers all four types. Changing plan takes effect immediately, and zones you already hold are unaffected either way.
Last reviewed 2026-08-23.
Open a ticket from the control panel, or use the contact form if you cannot sign in. If a domain is down, the status page is the fastest way to find out whether it is us.