Introducing the DNScale CLI
Manage zones and records, inspect DNSSEC, and read usage from your terminal with the DNScale CLI. Version 1.0.0 is available for macOS, Linux, and Windows.
The official DNScale CLI brings DNS operations to your terminal: list zones, inspect records, validate a change, and read signing status or usage with the same commands you can use in a shell script.
Version 1.0.0 is available for macOS, Linux, and Windows through GitHub Releases. On macOS and Linux, install it from the official Homebrew tap:
brew install dnscaleou/tap/dnscale
dnscale --versionThe release includes AMD64 and ARM64 binaries for macOS and Linux, a Windows AMD64 binary, and SHA-256 checksums. With Go 1.25 or newer, you can also run:
go install github.com/dnscaleou/dnscale-cli/cmd/dnscale@v1.0.0Start with the zones you can access
Create an API key with zones:read and records:read, supply it through your
secret manager as DNSCALE_API_KEY, then inspect your inventory:
dnscale zones list --all --json
dnscale records list example.com --all --jsonReplace example.com with an accessible zone. Zone arguments can be domain
names or UUIDs. --all collects every page before printing, so a script does
not accidentally treat the first page as the complete inventory.
The CLI quickstart covers installation, profiles, and a disposable sandbox workflow.
Keep credentials in named profiles
Save the environment key in your OS keychain when working interactively:
dnscale auth login --profile work
dnscale auth status --profile work
dnscale zones list --profile work --allA profile selects both a credential and its endpoint. An explicit profile
ignores an ambient API key, helping keep account selection clear when you
switch between projects. auth status reports local configuration without
checking the key against the API.
For CI and headless systems, keep using DNSCALE_API_KEY directly. The CLI
never loads .env files or accepts a token as a command-line argument. A
profile called sandbox does not simulate changes; use a real sandbox endpoint
and scoped key for test writes.
Check a record before submitting it
Save a request as record.json:
{"name":"_cli","type":"TXT","content":"first-value","ttl":300}Validate it locally:
dnscale records create example.com --file record.json --dry-run --jsonDry-run needs no credentials and sends no request. It reports
submitted: false, making it useful while editing a payload or checking JSON
generated by a script. It does not prove ownership, permissions, or server
acceptance.
Create and update accept flags, files, or JSON over stdin. The quickstart creates two TXT values, updates one, then deletes it while confirming its sibling remains. It also covers a detail that matters in scripts: an update can return a new record ID. Keep that ID for the next read or deletion.
Inspect DNSSEC and usage
With the corresponding API scopes, you can inspect signing status, retrieve public DS records, and check account or zone usage:
dnscale dnssec status example.com --profile work
dnscale dnssec ds example.com --profile work
dnscale usage current --profile work
dnscale usage zone example.com --profile workThese commands help bring account diagnostics into the same terminal session. DNSSEC inspection is read-only and does not replace checking delegation at your registrar.
Use the same interface in scripts and agents
Results are JSON by default; --json produces compact output. Errors go to
stderr, failures return nonzero exit codes, and responses retain request IDs
when the API supplies them. A command deadline includes name resolution,
pagination, and retry waits.
Safe reads can retry transient failures. Writes are never automatically
retried; inspect current state before repeating a write whose outcome is
uncertain. Deletion requires an explicit --yes.
Use the CLI for operational commands and shell automation. Use the Go SDK for DNS operations inside an application, or Terraform and DNSControl for declared DNS configuration. Give each record set a clear owner when combining these tools.
Explore the command reference, follow the first DNS workflow, or browse the source and issue tracker.
Managed authoritative DNS
Run DNS with observability built in
Start free, then move to Scale or custom plans when you need DNS traffic alerts, higher query volume, and dedicated human support.