All Products
Document Center

Alibaba Cloud DNS PrivateZone:Architecture

Last Updated:May 19, 2020

PrivateZone is a Domain Name System (DNS) that allows you to create records for domain or subdomain names that can only be accessed within one or more Virtual Private Clouds (VPCs). To use PrivateZone, follow these steps:

1 . Create a private zone, for example,

2 . Create a resource record in the private zone to determine how Alibaba Cloud DNS responds to DNS queries for a domain name, for example,

3 . Specify a VPC that you want to associate with the domain name.

After you complete the configurations, you can only visit through the associated VPC based on the private zone record you have specified. You can point the domain name to a specifically reserved IP address, such as


PrivateZone performs tunneling on your private domain name based on the tunneling feature of Alibaba Cloud VPC. For more information about tunneling, see Architecture of Alibaba Cloud VPC. A domain name can only be accessed within the associated VPCs, because each VPC has a unique tunnel ID.

In addition, Alibaba Cloud DNS uses strict verification measures to make sure that your domain name is unique throughout Alibaba Cloud. Only the owner of a domain name can manage the domain name.


A private zone, for example,, can be associated with one or more VPCs. Records in the private zone can be accessed in the associated VPCs.