Supported provider
Netlify DNS DNS, in the same place as everything else.
Does DNSMentor support Netlify DNS?
Yes. DNSMentor manages Netlify DNS DNS through its API, showing its zones alongside the other 25 supported providers in a single estate view. Every Netlify DNS change goes through the same 56 pre-flight checks, approval policy, independent verification and tamper-evident audit trail as every other provider.
Connecting Netlify DNS
- Create the credential in Netlify DNS Netlify → avatar (top right) → User settings → Applications → Personal access tokens → New access token. If the customer's team signs in with SAML, tick 'Allow access to my SAML-based Netlify team' when generating it or the token will not see their zones. The token inherits everything that Netlify user can do, in every team they belong to — there is no read-only or DNS-only token — so create it under a service account rather than an engineer's login. Give it an expiry only if you have a diary note to rotate it: an expired token, and a Netlify password reset, both revoke access without warning.
- Add the connection in DNSMentor Go to Admin → Providers & API keys, choose Netlify DNS, and paste the credential. DNSMentor stores it encrypted and strips it from every log and export.
- Sync the estate DNSMentor discovers every zone the Netlify DNS account holds and imports every record in them. This is a read operation — nothing is written to any zone.
- Group by client and start working Assign the imported domains to client portfolios, and the estate view, health scoring, checks and audit trail apply from that point on.
What Netlify DNS asks you for
The exact fields DNSMentor needs, and where in Netlify DNS to create them. Every secret is encrypted at rest and stripped by name from logs, exports and the audit trail.
Personal Access Token secret Netlify → avatar (top right) → User settings → Applications → Personal access tokens → New access token. If the customer's team signs in with SAML, tick 'Allow access to my SAML-based Netlify team' when generating it or the token will not see their zones. The token inherits everything that Netlify user can do, in every team they belong to — there is no read-only or DNS-only token — so create it under a service account rather than an engineer's login. Give it an expiry only if you have a diary note to rotate it: an expired token, and a Netlify password reset, both revoke access without warning.
Team Slug not secret Optional. Netlify → Team settings → General → Team details → 'Team slug', which is also the segment in app.netlify.com/teams/<slug>. Set it when the token can see more than one team and you want DNSMentor to list only this team's zones; leave it blank to list them all.
The sharp edge in Netlify DNS's API
Every provider API has one behaviour that catches integrations out. This is Netlify DNS's, and DNSMentor's adapter is written around it — the sort of thing you would otherwise discover during a migration.
What you get on top of the Netlify DNS console
One estate, not one provider
Netlify DNS zones sit beside every other provider your clients came with, grouped by the client who pays for them and searchable in one place.
56 checks before apply
The Netlify DNS console will accept a second SPF record or an MX pointing at an address without comment. DNSMentor will not.
Approval and audit
A second pair of eyes where policy requires it, and a hash-chained record of who changed what — neither of which a provider console offers.
Netlify DNS questions
Can I manage Netlify DNS DNS alongside my other providers?
Yes. DNSMentor connects Netlify DNS through its API and shows its zones in the same estate view as every other provider you connect — 26 are supported in total. Your engineers work in one interface instead of switching between provider portals, and the same checks, approval policy and audit trail apply regardless of which provider a domain happens to be with.
What credentials does DNSMentor need for Netlify DNS?
DNSMentor needs Personal Access Token, Team Slug for Netlify DNS. Netlify → avatar (top right) → User settings → Applications → Personal access tokens → New access token. If the customer's team signs in with SAML, tick 'Allow access to my SAML-based Netlify team' when generating it or the token will not see their zones. The token inherits everything that Netlify user can do, in every team they belong to — there is no read-only or DNS-only token — so create it under a service account rather than an engineer's login. Give it an expiry only if you have a diary note to rotate it: an expired token, and a Netlify password reset, both revoke access without warning.
Does DNSMentor move my zones away from Netlify DNS?
No. Your zones stay hosted at Netlify DNS and remain authoritative there. DNSMentor reads and writes through the Netlify DNS API, so nothing about your resolution path changes, and if you stop using DNSMentor the zones carry on exactly as they are.
Does DNSMentor validate Netlify DNS changes before applying them?
Yes. All 56 checks run against the zone as it would exist after the change, whichever provider hosts it. The change is then simulated, routed for approval if policy requires it, written through the Netlify DNS API after re-reading live state, and independently verified in public DNS afterwards.
Other providers DNSMentor manages
Connect Netlify DNS in about five minutes.
Paste one credential, sync, and see every zone in that account. It is a read operation — nothing is written until somebody presses apply.
No card. No trial clock. UK-hosted, and we will tell you which providers we have actually proven before you ask.
Last updated