zone [ ] { type ( master | primary ); allow-query { ; ... }; allow-query-on { ; ... }; allow-transfer { ; ... }; allow-update { ; ... }; also-notify [ port ] [ dscp ] { ( | [ port ] | [ port ] ) [ key ]; ... }; alt-transfer-source ( | * ) [ port ( | * ) ] [ dscp ]; alt-transfer-source-v6 ( | * ) [ port ( | * ) ] [ dscp ]; auto-dnssec ( allow | maintain | off ); check-dup-records ( fail | warn | ignore ); check-integrity ; check-mx ( fail | warn | ignore ); check-mx-cname ( fail | warn | ignore ); check-names ( fail | warn | ignore ); check-sibling ; check-spf ( warn | ignore ); check-srv-cname ( fail | warn | ignore ); check-wildcard ; database ; dialup ( notify | notify-passive | passive | refresh | ); dlz ; dnssec-dnskey-kskonly ; dnssec-loadkeys-interval ; dnssec-secure-to-insecure ; dnssec-update-mode ( maintain | no-resign ); file ; forward ( first | only ); forwarders [ port ] [ dscp ] { ( | ) [ port ] [ dscp ]; ... }; inline-signing ; ixfr-from-differences ; journal ; key-directory ; masterfile-format ( map | raw | text ); masterfile-style ( full | relative ); max-journal-size ( unlimited | ); max-records ; max-transfer-idle-out ; max-transfer-time-out ; max-zone-ttl ( unlimited | ); notify ( explicit | master-only | ); notify-delay ; notify-source ( | * ) [ port ( | * ) ] [ dscp ]; notify-source-v6 ( | * ) [ port ( | * ) ] [ dscp ]; notify-to-soa ; nsec3-test-zone ; // test only serial-update-method ( date | increment | unixtime ); sig-signing-nodes ; sig-signing-signatures ; sig-signing-type ; sig-validity-interval [ ]; update-check-ksk ; update-policy ( local | { ( deny | grant ) ( 6to4-self | external | krb5-self | krb5-selfsub | krb5-subdomain | ms-self | ms-selfsub | ms-subdomain | name | self | selfsub | selfwild | subdomain | tcp-self | wildcard | zonesub ) [ ] ; ... }; zero-no-soa-ttl ; zone-statistics ( full | terse | none | ); };