Zone Tags
Zone tags group zones by ownership, environment, or anything else your team already tracks. ZoneWatcher imports tags from providers that expose them, and lets you add custom tags that a sync will never overwrite.
Provider tags and custom tags
Every tag on a zone has an origin. A provider tag came from the DNS host and is refreshed the next time that zone syncs. A custom tag was added in ZoneWatcher. The same name can exist as both. Removing the provider copy leaves the custom tag in place, and the other way around.
Provider tags are read-only. Custom tags can be edited on the zone settings page, in bulk from the zone list, or through the API. Client users can see tags and cannot change them.
What gets imported
Cloudflare zone tags, Azure resource tags, and Amazon Route 53 hosted zone tags are imported as provider tags. Cloudflare resource tags are stored as key=value, or as the key alone when the value is empty. The API token has to be allowed to list account tags; a token limited to reading zones and DNS records cannot see them, and the tags already stored stay in place. Google Cloud labels, NS1 tags, Hetzner labels, Linode domain tags, and Oracle freeform and defined tags are imported the same way. Alibaba Cloud and Huawei Cloud public DNS tags are fetched alongside the zone list.
PowerDNS imports the zone account together with metadata that is safe to treat as a label. Kinds that carry secrets or transfer configuration, including anything containing TSIG, KEY, SECRET, or GSS, are left out. Digicert UltraDNS zone tags are imported from the zone tags endpoint.
A failed tag lookup leaves the previous provider tags for that host in place. A successful lookup replaces only that host's tags, including clearing them when the provider no longer sends any.
Filtering
The zone list and the zones table on a provider can be filtered by any tag on the team, whether it came from a provider or was added in ZoneWatcher. The API accepts filter[tag] with the exact tag name.