Audit Log
← Docs
Every DNS record change on your account is logged: who changed it, from what IP, when, and exactly what the value was before and after. This is the kind of trail auditors and security teams ask for.
Where to find it
Open Audit Log in the panel. Every create, update and delete across all your zones shows up here, newest first.

What's captured per entry
- Time (UTC) — exact timestamp, not "a few hours ago".
- Action — create / update / delete, color-coded.
- Zone & Record — which zone and which record name/type.
- Change — the actual before/after diff: old content → new content, TTL and priority changes shown separately.
- Actor — the username that made the change, tagged
apioruidepending on whether it came through the REST API or the panel. - IP — the client IP the change originated from.
Team accounts: this is the same trail that makes role-scoped
team access (see Team & RBAC)
actually accountable — you can see exactly which team member changed what,
not just that "someone with DNS Manager access" did.
Filtering & investigating
Narrow down by zone or action type. Useful when something broke and you need to know what changed right before — filter to the affected zone and scan the timeline around the incident time.
Exporting
Click Export CSV to download the current filtered view — hand it to a compliance reviewer, or pipe it into your own SIEM/log pipeline.
Typical uses
- Incident response — "the site was down between 14:02 and 14:05" → filter the zone, find the record that changed at 14:01.
- Compliance evidence — export the CSV as proof of change control for an audit.
- Catching mistakes early — a teammate with DNS Manager access made an unexpected change; the log shows exactly what and when, no guessing.